Back

HIGH

device-mapper-multipath: Regression of CVE-2022-41974 fix in Red Hat Enterprise Linux

Published Mar 29, 2023

Description

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

Affected products

Remediation

Red Hat statement

This issue only affected Red Hat Enterprise Linux 8.7 and Red Hat Enterprise Linux 9.1, which introduced this regression via the following errata: https://access.redhat.com/errata/RHBA-2022:7714 (Red Hat Enterprise Linux 8.7) https://access.redhat.com/errata/RHBA-2022:8313 (Red Hat Enterprise Linux 9.1) These errata provided updates for device-mapper-multipath packages, but did not include fixes for CVE-2022-41974. This issue did not affect Red Hat Enterprise Linux 8.6 or earlier, and Red Hat Enterprise Linux 9.0, as previously released fixes for CVE-2022-41974 were not regressed in those versions. For more details about the original security issue CVE-2022-41974, refer to the CVE page: https://access.redhat.com/security/cve/CVE-2022-41974.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 29, 2023
Updated Feb 18, 2025
Reserved Nov 1, 2022
CISA Vulnrichment
Updated Feb 18, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Nov 7, 2022
ENISA EUVD
Assigner redhat
Published Mar 29, 2023
Updated Feb 18, 2025
Exploited since n/a
EUVD-2022-43134