Lucene search

K
amazonAmazonALAS-2023-1833
HistorySep 13, 2023 - 11:15 p.m.

Medium: hwloc

2023-09-1323:15:00
alas.aws.amazon.com
8
open-mpi
denial of service
glibc-cpuset
topology-linux.c
update
hwloc 1.7-3.8.amzn1

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.0%

Issue Overview:

An issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of service or other unspecified impacts via glibc-cpuset in topology-linux.c. (CVE-2022-47022)

Affected Packages:

hwloc

Issue Correction:
Run yum update hwloc to update your system.

New Packages:

i686:  
    hwloc-debuginfo-1.7-3.8.amzn1.i686  
    hwloc-libs-1.7-3.8.amzn1.i686  
    hwloc-gui-1.7-3.8.amzn1.i686  
    hwloc-1.7-3.8.amzn1.i686  
    hwloc-devel-1.7-3.8.amzn1.i686  
  
src:  
    hwloc-1.7-3.8.amzn1.src  
  
x86_64:  
    hwloc-devel-1.7-3.8.amzn1.x86_64  
    hwloc-libs-1.7-3.8.amzn1.x86_64  
    hwloc-debuginfo-1.7-3.8.amzn1.x86_64  
    hwloc-1.7-3.8.amzn1.x86_64  
    hwloc-gui-1.7-3.8.amzn1.x86_64  

Additional References

Red Hat: CVE-2022-47022

Mitre: CVE-2022-47022

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

9.0%