The Device Mapper multipathing driver (aka multipath...
High severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Mar 26, 2026
Description
Published by the National Vulnerability Database
Mar 30, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Mar 26, 2026
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.
References