PT-2023-13556 · Unknown+4 · Device-Mapper-Multipath+4
Tomas Hoger
·
Published
2022-11-07
·
Updated
2025-02-18
·
CVE-2022-3787
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
device-mapper-multipath (affected versions not specified)
Description
A local privilege escalation issue exists, allowing local users to obtain root access by exploiting a flaw in the handling of UNIX domain sockets. This can be achieved by manipulating the multipath setup, taking advantage of the mishandling of repeated keywords when arithmetic ADD is used instead of bitwise OR.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Red Hat
Rocky Linux
Device-Mapper-Multipath