Race condition in Utilities for Amazon Elastic File System (EFS) - CVE-2022-46174
Published: January 31, 2023
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition within the Amazon EFS mount helper when using TLS to mount file systems. The mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel. As a result, concurrent mount operations can allocate the same local port, leading to either failed mount operations or an inappropriate mapping from an EFS customer’s local mount points to that customer’s EFS file systems.
Affected software
CSI Driver for Amazon EFS
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Red Hat OpenShift Container Platform
aws-efs-utils
amazon-efs-utils
How to mitigate CVE-2022-46174
CSI Driver for Amazon EFS - update to 1.4.8
Red Hat OpenShift Container Platform - update to 4.12.1
aws-efs-utils - addressed in versions 1.7-1.6.1, 1.34.5-150100.4.11.1
amazon-efs-utils - update to 1.35.0-1