First published: Tue May 09 2023(Updated: )
The device-mapper-multipath packages provide tools that use the device-mapper multipath kernel module to manage multipath devices.<br>Security Fix(es):<br><li> device-mapper-multipath: multipathd: insecure handling of files in /dev/shm leading to symlink attack (CVE-2022-41973)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/device-mapper-multipath | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-debugsource | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-debugsource | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-libs | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-libs | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-libs-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-libs-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/kpartx | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/kpartx-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/kpartx-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/libdmmp-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/libdmmp-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/kpartx | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-debugsource | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-libs | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-libs-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/kpartx | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/kpartx-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/libdmmp-debuginfo | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/device-mapper-multipath-debuginfo | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/device-mapper-multipath-debugsource | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/device-mapper-multipath-libs | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/device-mapper-multipath-libs-debuginfo | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/kpartx | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/kpartx-debuginfo | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/libdmmp-debuginfo | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
redhat/device-mapper-multipath-devel | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-devel | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-devel | <0.8.7-20.el9 | 0.8.7-20.el9 |
redhat/device-mapper-multipath-devel | <0.8.7-20.el9.aa | 0.8.7-20.el9.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:2459 is categorized as important due to the potential for a symlink attack.
To fix RHSA-2023:2459, update the affected device-mapper-multipath packages to version 0.8.7-20.el9 or later.
RHSA-2023:2459 describes a vulnerability in device-mapper-multipath that allows insecure handling of files in /dev/shm, leading to a symlink attack.
The affected packages in RHSA-2023:2459 include device-mapper-multipath, kpartx, and several debuginfo and debugsource packages.
A temporary workaround for RHSA-2023:2459 is to restrict access to the /dev/shm directory to reduce exposure to the symlink attack.