Race condition in Utilities for Amazon Elastic File System (EFS) - CVE-2022-46174

 

Race condition in Utilities for Amazon Elastic File System (EFS) - CVE-2022-46174

Published: January 31, 2023


Vulnerability identifier: #VU71689
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46174
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition within the Amazon EFS mount helper when using TLS to mount file systems. The mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. As a result, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems.


Affected software

Utilities for Amazon Elastic File System (EFS)
CSI Driver for Amazon EFS
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Red Hat OpenShift Container Platform
aws-efs-utils
amazon-efs-utils

How to mitigate CVE-2022-46174

Install updates from vendor's website.

Utilities for Amazon Elastic File System (EFS) - update to 1.34.4
CSI Driver for Amazon EFS - update to 1.4.8
Red Hat OpenShift Container Platform - update to 4.12.1
aws-efs-utils - addressed in versions 1.7-1.6.1, 1.34.5-150100.4.11.1
amazon-efs-utils - update to 1.35.0-1

External References

Related Security Bulletins