First published: Sat Sep 09 2023(Updated: )
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/pmix | <=5.0.0~rc1-2<=4.0.0-4.1<=4.2.2-1 | 5.0.1-1 4.2.2-1+deb12u1 4.0.0-4.1+deb11u1 |
ubuntu/pmix | <2.1.1~ | 2.1.1~ |
ubuntu/pmix | <3.1.5-1ubuntu0.1~ | 3.1.5-1ubuntu0.1~ |
ubuntu/pmix | <4.1.2-2ubuntu1+ | 4.1.2-2ubuntu1+ |
ubuntu/pmix | <5.0.1 | 5.0.1 |
debian/pmix | <=3.1.2-3 | 3.1.2-3+deb10u1 4.0.0-4.1+deb11u1 4.2.2-1+deb12u1 5.0.1-4 5.0.2-1.1 |
redhat/PMIx | <4.2.6 | 4.2.6 |
redhat/PMIx | <5.0.1 | 5.0.1 |
Openpmix Openpmix | <4.2.6 | |
Openpmix Openpmix | =5.0.0 | |
Fedora | =37 | |
Fedora | =38 | |
Fedora | =39 | |
Debian | =10.0 | |
Debian | =12.0 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Fedoraproject Fedora | =39 | |
OpenPMIx OpenPMIx | <4.2.6 | |
OpenPMIx OpenPMIx | =5.0.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41915 is a vulnerability in OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 that allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
CVE-2023-41915 has a severity rating of 8.1 (high).
CVE-2023-41915 affects OpenPMIx PMIx versions before 4.2.6 and 5.0.x before 5.0.1.
Attackers can exploit CVE-2023-41915 by leveraging a race condition during execution of library code with UID 0 to obtain ownership of arbitrary files.
You can find more information about CVE-2023-41915 in the OpenPMIx documentation (https://docs.openpmix.org/en/latest/security.html) and the release notes for versions 4.2.6 (https://github.com/openpmix/openpmix/releases/tag/v4.2.6) and 5.0.1 (https://github.com/openpmix/openpmix/releases/tag/v5.0.1).