CVE-2023-41915
published 2023-09-09CVE-2023-41915: OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code…
PriorityP344high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.12%
62.5th percentile
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | pmix | < pmix 4.2.2-1+deb12u1 (bookworm) | pmix 4.2.2-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_openmpi_4.1.7-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_pmix_4.1.3-1_on_cbl_mariner_2.0 | — | — |
| openpmix | openpmix | < 4.2.6 | 4.2.6 |
| openpmix | openpmix | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_oracle6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PMIx vulnerability
vendor_ubuntu·2023-10-17
CVE-2023-41915 PMIx vulnerability
Title: PMIx vulnerability
Summary: PMIx could be made to overwrite files.
Francois Diakhate discovered that PMIx did not properly handle race
conditions in the pmix library, which could lead to unwanted privilege
escalation. An attacker could possibly use this issue to obtain ownership
of an arbitrary file on the filesystem, under the default configuration
of the application.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
vendor_msrc·2023-09-12·CVSS 8.1
CVE-2023-41915 [HIGH] CWE-362 OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Marine
Red Hat
pmix: race condition allows attackers to obtain ownership of arbitrary files
vendor_redhat·2023-09-10·CVSS 8.1
CVE-2023-41915 [HIGH] CWE-362 pmix: race condition allows attackers to obtain ownership of arbitrary files
pmix: race condition allows attackers to obtain ownership of arbitrary files
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
OpenPMIx PMIx is vulnerable to a race condition during execution of library code with UID 0, which allows attackers to obtain ownership of arbitrary files.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Rest Services Manager (Netty) — CVE-2022-41915
vendor_oracle·2023-07-15·CVSS 6.5
CVE-2022-41915 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Rest Services Manager (Netty) — CVE-2022-41915
Oracle Oracle Communications Applications Risk Matrix: Rest Services Manager (Netty) vulnerability
CVE: CVE-2022-41915
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Debian
CVE-2023-41915: pmix - OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain own...
vendor_debian·2023·CVSS 8.1
CVE-2023-41915 [HIGH] CVE-2023-41915: pmix - OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain own...
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Scope: local
bookworm: resolved (fixed in 4.2.2-1+deb12u1)
bullseye: resolved (fixed in 4.0.0-4.1+deb11u1)
forky: resolved (fixed in 5.0.1-1)
sid: resolved (fixed in 5.0.1-1)
trixie: resolved (fixed in 5.0.1-1)
GHSA
GHSA-m8fg-c37h-w29q: OpenPMIx PMIx before 4
ghsa_unreviewed·2023-09-10
CVE-2023-41915 [HIGH] CWE-362 GHSA-m8fg-c37h-w29q: OpenPMIx PMIx before 4
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
OSV
CVE-2023-41915: OpenPMIx PMIx before 4
osv·2023-09-09·CVSS 8.1
CVE-2023-41915 [HIGH] CVE-2023-41915: OpenPMIx PMIx before 4
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/07/10/3http://www.openwall.com/lists/oss-security/2024/07/10/4http://www.openwall.com/lists/oss-security/2024/07/10/6http://www.openwall.com/lists/oss-security/2024/07/11/3https://docs.openpmix.org/en/latest/security.htmlhttps://github.com/openpmix/openpmix/releases/tag/v4.2.6https://github.com/openpmix/openpmix/releases/tag/v5.0.1https://lists.debian.org/debian-lts-announce/2023/10/msg00048.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFKIY6SNC3KQNZMVROWMIW6DI5XPNKQX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYJ7IRNR6NHJMTNOV3E3W3D5MLDRDCJX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDLWSMQYXF2ZGOQKCG26H6ZZA5FEH7HX/https://www.debian.org/security/2023/dsa-5547http://www.openwall.com/lists/oss-security/2024/07/10/3http://www.openwall.com/lists/oss-security/2024/07/10/4http://www.openwall.com/lists/oss-security/2024/07/10/6http://www.openwall.com/lists/oss-security/2024/07/11/3https://docs.openpmix.org/en/latest/security.htmlhttps://github.com/openpmix/openpmix/releases/tag/v4.2.6https://github.com/openpmix/openpmix/releases/tag/v5.0.1https://lists.debian.org/debian-lts-announce/2023/10/msg00048.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFKIY6SNC3KQNZMVROWMIW6DI5XPNKQX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYJ7IRNR6NHJMTNOV3E3W3D5MLDRDCJX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDLWSMQYXF2ZGOQKCG26H6ZZA5FEH7HX/https://www.debian.org/security/2023/dsa-5547
2023-09-09
Published