UbuntuUpdates.org

Package "multipath-tools"

Name: multipath-tools

Description:

maintain multipath block device access

Latest version: 0.8.3-1ubuntu2.1
Release: focal (20.04)
Level: security
Repository: main
Homepage: http://christophe.varoqui.free.fr/

Links


Download "multipath-tools"


Other versions of "multipath-tools" in Focal

Repository Area Version
base main 0.8.3-1ubuntu2
updates main 0.8.3-1ubuntu2.4

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 0.8.3-1ubuntu2.1 2022-11-17 15:07:24 UTC

  multipath-tools (0.8.3-1ubuntu2.1) focal-security; urgency=medium

  * SECURITY UPDATE: symlink attack
    - debian/patches/CVE-2022-41973.patch: use /run instead of /dev/shm in
      .gitignore, Makefile.inc, libmultipath/defaults.h,
      multipath/Makefile, multipath/multipath.rules.in,
      multipath/tmpfiles.conf.in.
    - debian/multipath-tools.install, debian/multipath-udeb.install:
      install tmpfiles.d/multipath.conf.
    - debian/rules: copy udev rule after build.
    - CVE-2022-41973
  * SECURITY UPDATE: authorization bypass
    - debian/patches/CVE-2022-41974.patch: ignore duplicated multipathd
      command keys in multipathd/main.c, multipathd/cli.c.
    - CVE-2022-41974

 -- Marc Deslauriers <email address hidden> Mon, 31 Oct 2022 11:14:23 -0400

CVE-2022-41973 multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local use
CVE-2022-41974 multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973.



About   -   Send Feedback to @ubuntu_updates