Lucene search

K
cvelistRedhatCVELIST:CVE-2022-3787
HistoryMar 29, 2023 - 12:00 a.m.

CVE-2022-3787

2023-03-2900:00:00
CWE-285
redhat
www.cve.org
2
vulnerability
device-mapper-multipath
local users
root access
unix domain sockets
access controls
multipath setup
privilege escalation

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "device-mapper-multipath",
    "versions": [
      {
        "version": "unknown",
        "status": "affected"
      }
    ]
  }
]