CVE-2023-41915: Race Condition
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-41915?
CVE-2023-41915 is a vulnerability in OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 that allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
How severe is CVE-2023-41915?
CVE-2023-41915 has a severity rating of 8.1 (high).
Which software versions are affected by CVE-2023-41915?
CVE-2023-41915 affects OpenPMIx PMIx versions before 4.2.6 and 5.0.x before 5.0.1.
How can an attacker exploit CVE-2023-41915?
Attackers can exploit CVE-2023-41915 by leveraging a race condition during execution of library code with UID 0 to obtain ownership of arbitrary files.
Where can I find more information about CVE-2023-41915?
You can find more information about CVE-2023-41915 in the OpenPMIx documentation (https://docs.openpmix.org/en/latest/security.html) and the release notes for versions 4.2.6 (https://github.com/openpmix/openpmix/releases/tag/v4.2.6) and 5.0.1 (https://github.com/openpmix/openpmix/releases/tag/v5.0.1).