QID 199001
QID 199001: Authorization bypass and symlink attack in multipathd (Leeloo Multipath)
The authorization bypass (CVE-2022-41974) was introduced in February 2017 (version 0.7.0) by commit 9acda0c ("Perform socket client uid check on IPC commands"), but earlier versions perform no authorization checks at all: any unprivileged local user can issue any privileged command to multipathd. The symlink attack (CVE-2022-41973) was introduced in May 2018 (version.7.7) by commit 65d0a63 ("functions to indicate mapping failure in /dev/shm"); the vulnerable code was hardened significantly in May 2020 (version 0.8.5) by commit 40ee3ea ("simplify failed wwid code"), but it remains exploitable nonetheless.
Attackers can exploit these flaw to bypass multipathd's authorization check.
Solution
Update to latest version.
Leeloo Multipath for affected packages and patching details.
Leeloo Multipath for affected packages and patching details.
Vendor References
- Leeloo Multipath -
www.qualys.com/2022/10/24/leeloo-multipath/leeloo-multipath.txt
CVEs related to QID 199001
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 41973 | Ubuntu |
|