VDB
ALINUX2-SA-2022%3A0050
ALINUX2-SA-2022%3A0050
PUBLISHED
CVSS 8.399999618530273 HIGH
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2022-41974: multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
Risk Scores
CVSS 3.1
8.399999618530273
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | device-mapper-multipath |
Timeline
- Oct 27, 2022 CVE Published
- Oct 27, 2022 CVE Updated