Logo
vulnerabilityCVE-2022-41974
Name
CVE-2022-41974
Source
NVD ( link)Debian ( link)
Description
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
multipath-tools
Exploitable

Vulnerability Rating#


7.8
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.9.8
Not Affected
buildroot
master
0.9.8
Not Affected
yocto
master
0.12.2
Not Affected
yocto
scarthgap
0.9.8
Not Affected