CVE-2022-3787
Summary
| CVE | CVE-2022-3787 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-29 21:15:00 UTC |
| Updated | 2023-04-06 19:25:00 UTC |
| Description | A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Device-mapper-multipath | - | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.7 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 9.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2138959 – (CVE-2022-3787) CVE-2022-3787 device-mapper-multipath: Regression of CVE-2022-41974 fix in Red Hat Enterprise Linux | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160256 Oracle Enterprise Linux Security Update for device-mapper-multipath (ELSA-2022-7928)
- 160328 Oracle Enterprise Linux Security Update for device-mapper-multipath (ELSA-2022-8453)
- 240861 Red Hat Update for device-mapper-multipath (RHSA-2022:7928)
- 240916 Red Hat Update for device-mapper-multipath (RHSA-2022:8453)
- 355168 Amazon Linux Security Advisory for device-mapper-multipath : ALAS2023-2023-126
- 377789 Alibaba Cloud Linux Security Update for device-mapper-multipath (ALINUX3-SA-2022:0185)
- 940778 AlmaLinux Security Update for device-mapper-multipath (ALSA-2022:7928)
- 940786 AlmaLinux Security Update for device-mapper-multipath (ALSA-2022:8453)
- 960474 Rocky Linux Security Update for device-mapper-multipath (RLSA-2022:7928)
- 960571 Rocky Linux Security Update for device-mapper-multipath (RLSA-2022:8453)