Unrated severityNVD Advisory· Published Sep 9, 2023· Updated Aug 2, 2024
CVE-2023-41915
CVE-2023-41915
Description
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- OpenPMIx/PMIxdescription
- osv-coords9 versionspkg:rpm/almalinux/pmixpkg:rpm/almalinux/pmix-develpkg:rpm/almalinux/pmix-pmipkg:rpm/almalinux/pmix-pmi-develpkg:rpm/almalinux/pmix-toolspkg:rpm/opensuse/pmix&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pmix&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/pmix&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/pmix&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP5
< 3.2.3-5.el9+ 8 more
- (no CPE)range: < 3.2.3-5.el9
- (no CPE)range: < 3.2.3-5.el9
- (no CPE)range: < 3.2.3-5.el9
- (no CPE)range: < 3.2.3-5.el9
- (no CPE)range: < 3.2.3-5.el9
- (no CPE)range: < 3.2.3-150300.3.8.1
- (no CPE)range: < 3.2.3-150300.3.8.1
- (no CPE)range: < 3.2.3-150300.3.8.1
- (no CPE)range: < 3.2.3-150300.3.8.1
Patches
Vulnerability mechanics
References
12- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFKIY6SNC3KQNZMVROWMIW6DI5XPNKQX/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYJ7IRNR6NHJMTNOV3E3W3D5MLDRDCJX/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDLWSMQYXF2ZGOQKCG26H6ZZA5FEH7HX/mitrevendor-advisory
- www.debian.org/security/2023/dsa-5547mitrevendor-advisory
- www.openwall.com/lists/oss-security/2024/07/10/3mitremailing-list
- www.openwall.com/lists/oss-security/2024/07/10/4mitremailing-list
- www.openwall.com/lists/oss-security/2024/07/10/6mitremailing-list
- www.openwall.com/lists/oss-security/2024/07/11/3mitremailing-list
- lists.debian.org/debian-lts-announce/2023/10/msg00048.htmlmitremailing-list
- docs.openpmix.org/en/latest/security.htmlmitre
- github.com/openpmix/openpmix/releases/tag/v4.2.6mitre
- github.com/openpmix/openpmix/releases/tag/v5.0.1mitre
News mentions
0No linked articles in our index yet.