Lucene search

K
f5F5F5:K000133058
HistoryMar 18, 2023 - 12:00 a.m.

K000133058 : device-mapper-multipath vulnerability CVE-2022-41973

2023-03-1800:00:00
my.f5.com
7
device-mapper-multipath
multipath-tools
local privilege escalation
controlled file writes
symlink handling
cve-2022-41973

7.8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Security Advisory Description

multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root. (CVE-2022-41973)

Impact

There is no impact; F5 products are not affected by this vulnerability.