CVE-2022-41973
published 2022-10-29CVE-2022-41973: multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.66%
47.4th percentile
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | multipath-tools | < multipath-tools 0.9.4-1 (bookworm) | multipath-tools 0.9.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl2_device-mapper-multipath_0.8.6-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_device-mapper-multipath_0.8.6-1_on_cbl_mariner_1.0 | — | — |
| opensvc | multipath-tools | >= 0 < 0.8.5-2+deb11u1 | 0.8.5-2+deb11u1 |
| opensvc | multipath-tools | >= 0 < 0.9.4-1 | 0.9.4-1 |
| opensvc | multipath-tools | >= 0 < 0.9.4-1 | 0.9.4-1 |
| opensvc | multipath-tools | >= 0 < 0.9.4-1 | 0.9.4-1 |
| opensvc | multipath-tools | >= 0 < 0.7.4-2ubuntu3.2 | 0.7.4-2ubuntu3.2 |
| opensvc | multipath-tools | >= 0 < 0.8.3-1ubuntu2.1 | 0.8.3-1ubuntu2.1 |
| opensvc | multipath-tools | >= 0 < 0.8.8-1ubuntu1.22.04.1 | 0.8.8-1ubuntu1.22.04.1 |
| opensvc | multipath-tools | >= 0.7.0 < 0.9.2 | 0.9.2 |
| opensvc | multipath-tools | >= 0.7.7 < 0.9.2 | 0.9.2 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
multipath-tools vulnerabilities
vendor_ubuntu·2022-11-17·CVSS 7.8
CVE-2022-41974 [HIGH] multipath-tools vulnerabilities
Title: multipath-tools vulnerabilities
Summary: Several security issues were fixed in multipath-tools.
It was discovered that multipath-tools incorrectly handled symlinks. A
local attacker could possibly use this issue, in combination with other
issues, to escalate privileges. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-41973)
It was discovered that multipath-tools incorrectly handled access controls.
A local attacker could possibly use this issue, in combination with other
issues, to escalate privileges. (CVE-2022-41974)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
device-mapper-multipath: Regression of CVE-2022-41974 fix in Red Hat Enterprise Linux
vendor_redhat·2022-11-07·CVSS 7.8
CVE-2022-3787 [HIGH] CWE-285 device-mapper-multipath: Regression of CVE-2022-41974 fix in Red Hat Enterprise Linux
device-mapper-multipath: Regression of CVE-2022-41974 fix in Red Hat Enterprise Linux
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to U
Red Hat
device-mapper-multipath: multipathd: insecure handling of files in /dev/shm leading to symlink attack
vendor_redhat·2022-10-24·CVSS 7.8
CVE-2022-41973 [HIGH] device-mapper-multipath: multipathd: insecure handling of files in /dev/shm leading to symlink attack
device-mapper-multipath: multipathd: insecure handling of files in /dev/shm leading to symlink attack
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, in conjunction with CVE-2022-41974. Local users that are able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which may lead to control
Red Hat
device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket
vendor_redhat·2022-10-24·CVSS 7.8
CVE-2022-41974 [HIGH] CWE-285 device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket
device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain
Microsoft
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in mu
vendor_msrc·2022-10-11·CVSS 7.8
CVE-2022-41973 [HIGH] CWE-59 multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in mu
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to tr
Microsoft
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can
vendor_msrc·2022-10-11·CVSS 7.8
CVE-2022-41974 [HIGH] CWE-269 multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword which is mishandled because arithmetic ADD is used instead of bitwise OR.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
Oracle
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) — CVE-2021-41973
vendor_oracle·2022-04-15·CVSS 6.5
CVE-2021-41973 [MEDIUM] Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) — CVE-2021-41973
Oracle Oracle Support Tools Risk Matrix: Diagnostic Assistant (Apache MINA) vulnerability
CVE: CVE-2021-41973
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Debian
CVE-2022-41974: multipath-tools - multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain ro...
vendor_debian·2022·CVSS 7.8
CVE-2022-41974 [HIGH] CVE-2022-41974: multipath-tools - multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain ro...
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
Scope: local
bookworm: resolved (fixed in 0.9.4-1)
bullseye: resolved (fixed in 0.8.5-2+deb11u1)
forky: resolved (fixed in 0.9.4-1)
sid: resolved (fixed in 0.9.4-1)
trixie: resolved (fixed in 0.9.4-1)
Debian
CVE-2022-41973: multipath-tools - multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain ro...
vendor_debian·2022·CVSS 7.8
CVE-2022-41973 [HIGH] CVE-2022-41973: multipath-tools - multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain ro...
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
Scope: local
bookworm: resolved (fixed in 0.9.4-1)
bullseye: resolved (fixed in 0.8.5-2+deb11u1)
forky: resolved (fixed in 0.9.4-1)
sid: resolved (fixed in 0.9.4-1)
trixie: resolved (fixed in 0.9.4-1)
GHSA
GHSA-m46g-8pc6-m8q7: A vulnerability was found in the device-mapper-multipath
ghsa_unreviewed·2023-03-29·CVSS 7.8
CVE-2022-3787 [HIGH] CWE-285 GHSA-m46g-8pc6-m8q7: A vulnerability was found in the device-mapper-multipath
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in conjunction with CVE-2022-41973. Local users that are able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This issue occurs because an attacker can repeat a keyword, which is mishandled when arithmetic ADD is used instead of bitwise OR. This could lead to local privilege escalation to root.
OSV
multipath-tools vulnerabilities
osv·2022-11-17·CVSS 7.8
CVE-2022-41973 [HIGH] multipath-tools vulnerabilities
multipath-tools vulnerabilities
It was discovered that multipath-tools incorrectly handled symlinks. A
local attacker could possibly use this issue, in combination with other
issues, to escalate privileges. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-41973)
It was discovered that multipath-tools incorrectly handled access controls.
A local attacker could possibly use this issue, in combination with other
issues, to escalate privileges. (CVE-2022-41974)
GHSA
GHSA-46cw-54vx-86g5: multipath-tools 0
ghsa_unreviewed·2022-10-30·CVSS 7.8
CVE-2022-41974 [HIGH] CWE-269 GHSA-46cw-54vx-86g5: multipath-tools 0
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
GHSA
GHSA-6c7c-85qv-wvgp: multipath-tools 0
ghsa_unreviewed·2022-10-29·CVSS 7.8
CVE-2022-41973 [HIGH] CWE-59 GHSA-6c7c-85qv-wvgp: multipath-tools 0
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
OSV
CVE-2022-41973: multipath-tools 0
osv·2022-10-29·CVSS 7.8
CVE-2022-41973 [HIGH] CVE-2022-41973: multipath-tools 0
multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users able to access /dev/shm can change symlinks in multipathd due to incorrect symlink handling, which could lead to controlled file writes outside of the /dev/shm directory. This could be used indirectly for local privilege escalation to root.
OSV
CVE-2022-41974: multipath-tools 0
osv·2022-10-29·CVSS 7.8
CVE-2022-41974 [HIGH] CVE-2022-41974: multipath-tools 0
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.
No detection rules found.
No public exploits indexed.
Qualys
Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328) | Qualys
blogs_qualys·2022-11-30·CVSS 7.8
CVE-2022-3328 [HIGH] Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328) | Qualys
#### Table of Contents
- What is snap-confine?
- Potential Impact
- The technical details of snap-confine vulnerability can be found at:
- Disclosure Timeline
- Qualys QID Coverage
- Discover Vulnerable Linux Servers Using Qualys Cloud Platform
- Vendor References
- Frequently Asked Questions (FAQs)
The Qualys Threat Research Unit (TRU) has discovered a new vulnerability in snap-confine function on Linux operating systems, a SUID-root program installed by default on Ubuntu. Qualys recommends that security teams apply the patch for this vulnerability as soon as possible.
In February 2022, Qualys Threat Research Unit (TRU) published CVE-2021-44731 in our “Lemmings” advisory. The vulnerability (CVE-2022-3328) was introduced in February 2022 by the patch for CVE-2021-44731)
The Qualys Thre
Qualys
Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328)
blogs_qualys·2022-11-30·CVSS 7.8
[HIGH] Snapd Race Condition Vulnerability in snap-confine’s must_mkdir_and_open_with_perms() (CVE-2022-3328)
## Table of Contents
What is snap-confine?
Potential Impact
The technical details of snap-confine vulnerability can be found at:
Disclosure Timeline
Qualys QID Coverage
Discover Vulnerable Linux Servers Using Qualys Cloud Platform
Vendor References
Frequently Asked Questions (FAQs)
The Qualys Threat Research Unit (TRU) has discovered a new vulnerability in snap-confine function on Linux operating systems, a SUID-root program installed by default on Ubuntu. Qualys recommends that security teams apply the patch for this vulnerability as soon as possible.
In February 2022, Qualys Threat Research Unit (TRU) published CVE-2021-44731 in our “Lemmings” advisory. The vulnerability (CVE-2022-3328) was introduced in February 2022 by the patch for CVE-2021-44731)
The Qualys Threat Research
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
## Table of Contents
Microsoft Patch Tuesday Summary
The November 2022 Microsoft Vulnerabilities are Classified as Follows:
OpenSSL 3.x Critical Vulnerability Highlights
OpenSSL 3.x Related Blogs and Resources
Microsoft Addressed Six Zero-Day Vulnerabilities
Microsoft Patch Tuesday Critical Vulnerability Highlights
Microsoft Release Summary
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response with Patch Management (PM)
Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Patch Tuesday Is
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The November 2022 Microsoft Vulnerabilities are Classified as Follows:
- OpenSSL 3.x Critical Vulnerability Highlights
- OpenSSL 3.x Related Blogs and Resources
- Microsoft Addressed Six Zero-Day Vulnerabilities
- Microsoft Patch Tuesday Critical Vulnerability Highlights
- Microsoft Release Summary
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response with Patch Management (PM)
- Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
- Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Qualys
Qualys Research Team: Threat Thursdays, October 2022 | Qualys
blogs_qualys·2022-10-28·CVSS 7.8
[HIGH] Qualys Research Team: Threat Thursdays, October 2022 | Qualys
#### Table of Contents
- From the Qualys Blog
- New Tools & Techniques
- New Vulnerabilities
- Noteworthy Mentions
- Threat Thursdays Webinar
Welcome to the third edition of the Qualys Research Team’s “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. Feedback on our second edition, Qualys Threat Research Thursday, is more than welcome. We would love to hear from you!
## From the Qualys Blog
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
- Qualys Response to ProxyNotShell Microsoft Exchange Server Zero-Day Threat Using Qualys Cloud Platform – How do you detect the ProxyNotShell vulnerability that was released
Qualys
Leeloo Multipath: Authorization bypass and symlink attack in multipathd (CVE-2022-41974 and CVE-2022-41973) | Qualys
blogs_qualys·2022-10-26·CVSS 7.8
CVE-2022-41974 [HIGH] Leeloo Multipath: Authorization bypass and symlink attack in multipathd (CVE-2022-41974 and CVE-2022-41973) | Qualys
#### Table of Contents
- About multipathd
- Potential Impact of Leeloo Multipath
- Technical Details of Leeloo Multipath
- Disclosure Timeline:
- Qualys QID Coverage
- Discover Vulnerable Linux Servers Using Qualys VMDR
- Vendor References
- Frequently Asked Questions (FAQs)
- Contributors:
The Qualys Research Team has discovered two vulnerabilities in multipathd, the most important of which can be exploited for authorization bypass. Qualys recommends security teams apply patches for these vulnerabilities as soon as possible.
The Qualys Research Team combined these two vulnerabilities with the third vulnerability in another package installed by default on Ubuntu Server and obtained full root privileges on Ubuntu Server 22.04; other releases are probably also exploitable. We will publish
Qualys
Leeloo Multipath: Authorization bypass and symlink attack in multipathd (CVE-2022-41974 and CVE-2022-41973)
blogs_qualys·2022-10-26·CVSS 7.8
[HIGH] Leeloo Multipath: Authorization bypass and symlink attack in multipathd (CVE-2022-41974 and CVE-2022-41973)
## Table of Contents
About multipathd
Potential Impact of Leeloo Multipath
Technical Details of Leeloo Multipath
Disclosure Timeline:
Qualys QID Coverage
Discover Vulnerable Linux Servers Using Qualys VMDR
Vendor References
Frequently Asked Questions (FAQs)
Contributors:
The Qualys Research Team has discovered two vulnerabilities in multipathd, the most important of which can be exploited for authorization bypass. Qualys recommends security teams apply patches for these vulnerabilities as soon as possible.
The Qualys Research Team combined these two vulnerabilities with the third vulnerability in another package installed by default on Ubuntu Server and obtained full root privileges on Ubuntu Server 22.04; other releases are probably also exploitable. We will publish this third
http://packetstormsecurity.com/files/169611/Leeloo-Multipath-Authorization-Bypass-Symlink-Attack.htmlhttp://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlhttp://seclists.org/fulldisclosure/2022/Dec/4http://seclists.org/fulldisclosure/2022/Oct/25http://www.openwall.com/lists/oss-security/2022/10/24/2http://www.openwall.com/lists/oss-security/2022/11/30/2https://bugzilla.suse.com/show_bug.cgi?id=1202739https://github.com/opensvc/multipath-tools/releases/tag/0.9.2https://lists.debian.org/debian-lts-announce/2022/12/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QIGZM5NOOMFDCITOLQEJNNX5SCRQLQVV/https://security.gentoo.org/glsa/202311-06https://www.debian.org/security/2023/dsa-5366https://www.qualys.com/2022/10/24/leeloo-multipath/leeloo-multipath.txthttp://packetstormsecurity.com/files/169611/Leeloo-Multipath-Authorization-Bypass-Symlink-Attack.htmlhttp://packetstormsecurity.com/files/170176/snap-confine-must_mkdir_and_open_with_perms-Race-Condition.htmlhttp://seclists.org/fulldisclosure/2022/Dec/4http://seclists.org/fulldisclosure/2022/Oct/25http://www.openwall.com/lists/oss-security/2022/10/24/2http://www.openwall.com/lists/oss-security/2022/11/30/2https://bugzilla.suse.com/show_bug.cgi?id=1202739https://github.com/opensvc/multipath-tools/releases/tag/0.9.2https://lists.debian.org/debian-lts-announce/2022/12/msg00037.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QIGZM5NOOMFDCITOLQEJNNX5SCRQLQVV/https://security.gentoo.org/glsa/202311-06https://www.debian.org/security/2023/dsa-5366https://www.qualys.com/2022/10/24/leeloo-multipath/leeloo-multipath.txt
2022-10-29
Published