device-mapper-multipath: Regression of CVE-2022-41974 fix in Red Hat Enterprise Linux
Published Mar 29, 2023
8.4
HIGHCVSS 3.1
EPSS 0.22%
Description
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
Affected products
- Vendor n/a Product Device-Mapper-Multipath Defaultn/a
- Version unknownStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Device-Mapper-Multipath | n/a |
|
- n/a
- 8.7
- 9.1
No data.
Red Hat Enterprise Linux 8
device-mapper-multipath-0:0.8.4-28.el8_7.1
Fixed · RHSA-2022:7928
Red Hat Enterprise Linux 9
device-mapper-multipath-0:0.8.7-12.el9_1.1
Fixed · RHSA-2022:8453
Red Hat Enterprise Linux 6
device-mapper-multipath
Not affected
Red Hat Enterprise Linux 7
device-mapper-multipath
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | device-mapper-multipath-0:0.8.4-28.el8_7.1 | Fixed | RHSA-2022:7928 |
| Red Hat Enterprise Linux 9 | device-mapper-multipath-0:0.8.7-12.el9_1.1 | Fixed | RHSA-2022:8453 |
| Red Hat Enterprise Linux 6 | device-mapper-multipath | Not affected | n/a |
| Red Hat Enterprise Linux 7 | device-mapper-multipath | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affected Red Hat Enterprise Linux 8.7 and Red Hat Enterprise Linux 9.1, which introduced this regression via the following errata: https://access.redhat.com/errata/RHBA-2022:7714 (Red Hat Enterprise Linux 8.7) https://access.redhat.com/errata/RHBA-2022:8313 (Red Hat Enterprise Linux 9.1) These errata provided updates for device-mapper-multipath packages, but did not include fixes for CVE-2022-41974. This issue did not affect Red Hat Enterprise Linux 8.6 or earlier, and Red Hat Enterprise Linux 9.0, as previously released fixes for CVE-2022-41974 were not regressed in those versions. For more details about the original security issue CVE-2022-41974, refer to the CVE page: https://access.redhat.com/security/cve/CVE-2022-41974.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-3787 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2138959 Issue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43134 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3787
- https://www.cve.org/CVERecord?id=CVE-2022-3787
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3787 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2138959 | Issue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43134 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3787 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3787 |
Change history (0)
No recorded changes yet.