Logo
vulnerabilityCVE-2022-41973
Name
CVE-2022-41973
Source
NVD ( link)Debian ( link)
Description
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
multipath-tools
Exploitable

Vulnerability Rating#


7.8
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.9.8
Not Affected
buildroot
master
0.9.8
Not Affected
yocto
master
0.12.2
Not Affected
yocto
scarthgap
0.9.8
Not Affected