First published: Tue Oct 17 2023(Updated: )
Francois Diakhate discovered that PMIx did not properly handle race conditions in the pmix library, which could lead to unwanted privilege escalation. An attacker could possibly use this issue to obtain ownership of an arbitrary file on the filesystem, under the default configuration of the application.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libpmix-bin | <4.1.2-2ubuntu1+esm1 | 4.1.2-2ubuntu1+esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libpmix2 | <4.1.2-2ubuntu1+esm1 | 4.1.2-2ubuntu1+esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/python3-pmix | <4.1.2-2ubuntu1+esm1 | 4.1.2-2ubuntu1+esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libpmi1-pmix | <3.1.5-1ubuntu0.1~esm1 | 3.1.5-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libpmi2-pmix | <3.1.5-1ubuntu0.1~esm1 | 3.1.5-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libpmix2 | <3.1.5-1ubuntu0.1~esm1 | 3.1.5-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/libpmi1-pmix | <2.1.1~rc1-1ubuntu0.1~esm1 | 2.1.1~rc1-1ubuntu0.1~esm1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libpmi2-pmix | <2.1.1~rc1-1ubuntu0.1~esm1 | 2.1.1~rc1-1ubuntu0.1~esm1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/libpmix2 | <2.1.1~rc1-1ubuntu0.1~esm1 | 2.1.1~rc1-1ubuntu0.1~esm1 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of USN-6434-1 is CVE-2023-41915.
The severity of CVE-2023-41915 is not provided in the information.
The affected software is libpmix-bin, libpmix2, python3-pmix, libpmi1-pmix, libpmi2-pmix, and libpmix2.
To fix CVE-2023-41915, update the affected software to version 4.1.2-2ubuntu1+esm1 for libpmix-bin, libpmix2, and python3-pmix, and version 3.1.5-1ubuntu0.1~esm1 for libpmi1-pmix and libpmi2-pmix.
You can find more information about USN-6434-1 at the following references: [USN-6434-1](https://ubuntu.com/security/notices/USN-6434-1) and [CVE-2023-41915](https://ubuntu.com/security/CVE-2023-41915).