Race condition in Paramiko - CVE-2022-24302

 

Race condition in Paramiko - CVE-2022-24302

Published: March 28, 2022


Vulnerability identifier: #VU61662
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24302
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to a race condition in the write_private_key_file() function between creation and chmod operations. A local user can exploit the race and gain unauthorized access to sensitive information.


Affected software

Paramiko
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 1000X
PowerStore 3000X
PowerStoreX OS
SUSE Manager Server
SUSE Manager Proxy
Fedora
SUSE Manager Tools
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
openSUSE Leap
Ubuntu
openEuler
Red Hat OpenShift Container Platform
IBM Netezza Analytics
IBM Integrated Analytics System
Cloud Pak for Security (CP4S)
python3-paramiko (Ubuntu package)
paramiko-doc (Ubuntu package)
python-paramiko (Ubuntu package)
python3-paramiko
python-paramiko-doc
python-paramiko
python-paramiko (Red Hat package)
python2-paramiko
python-paramiko-help
venv-salt-minion
IBM Cloud Pak for Data System
Red Hat OpenStack
PowerStore X
PowerStore T
IBM Cloud Pak for Watson AIOps
EMC ECS

How to mitigate CVE-2022-24302

Install updates from vendor's website.

Paramiko - update to 2.10.1
Red Hat OpenShift Container Platform - addressed in versions 4.11.20, 4.12.0
IBM Integrated Analytics System - update to 1.0.28.0
Cloud Pak for Security (CP4S) - update to 1.10.8.0
python3-paramiko (Ubuntu package) - addressed in versions 1.16.01ubuntu0.2+esm2, 2.0.0-1ubuntu1.3, 2.6.0-2ubuntu0.1, 2.7.2-1ubuntu1.1
paramiko-doc (Ubuntu package) - update to 1.16.01ubuntu0.2+esm2
python-paramiko (Ubuntu package) - addressed in versions 1.16.01ubuntu0.2+esm2, 2.0.0-1ubuntu1.3
IBM Cloud Pak for Data System - update to 2.0.2.1
python3-paramiko - addressed in versions 2.4.0-9.13.1, 2.4.2-150100.6.12.1
python-paramiko-doc - addressed in versions 2.4.0-9.13.1, 2.4.2-150100.6.12.1
python-paramiko - update to 2.4.0-9.13.1
python-paramiko (Red Hat package) - update to 2.4.2-8.el8ost
python2-paramiko - update to 2.4.2-150100.6.12.1
python-paramiko - addressed in versions 2.4.3-2.el8, 2.10.3-1.fc34, 2.10.3-1.fc35, 2.10.3-1.fc36
python-paramiko - update to 2.7.2-2
python-paramiko-help - update to 2.7.2-2
python3-paramiko - update to 2.7.2-2
PowerStore X - update to 3.2.1.0-1989710
PowerStore T - update to 3.2.1.0-1989710
PowerStoreX OS - update to 3.2.1.6-2476179
IBM Cloud Pak for Watson AIOps - update to 3.5
EMC ECS - update to 3.7.0.3
IBM Netezza Analytics - update to 11.2.29
Red Hat OpenStack - addressed in versions 16.1.9, 16.2.4
venv-salt-minion - update to 3004-3.9.1

External References

Related Security Bulletins