Race condition in Openpmix - CVE-2023-41915

 

Race condition in Openpmix - CVE-2023-41915

Published: September 19, 2023


Vulnerability identifier: #VU80882
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41915
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition when the PMIx library called is called by a process
running as uid 0. A local user can exploit the race and obtain ownership of an arbitrary file on the filesystem.


Affected software

Openpmix
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
Anolis OS
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
HPC Module
openSUSE Leap
Ubuntu
openEuler
Fedora
libpmi2-pmix (Ubuntu package)
libpmi1-pmix (Ubuntu package)
python3-pmix (Ubuntu package)
libpmix2 (Ubuntu package)
libpmix-bin (Ubuntu package)
pmix (Red Hat package)
pmix
pmix-devel
pmix-mca-params
libpmix2-debuginfo
libmca_common_dstore1-debuginfo
pmix-plugins
pmix-plugin-munge
pmix-test-debuginfo
pmix-plugins-debuginfo
pmix-headers
pmix-debugsource
pmix-debuginfo
libmca_common_dstore1
libpmix2
pmix-test
pmix-plugin-munge-debuginfo
pmix (Debian package)
pmix-tools
pmix-doc

How to mitigate CVE-2023-41915

Install updates from vendor's website.

Openpmix - addressed in versions 4.2.6, 5.0.1
libpmi2-pmix (Ubuntu package) - update to Ubuntu Pro
libpmi1-pmix (Ubuntu package) - update to Ubuntu Pro
python3-pmix (Ubuntu package) - update to Ubuntu Pro
libpmix2 (Ubuntu package) - update to Ubuntu Pro
libpmix-bin (Ubuntu package) - update to Ubuntu Pro
pmix (Red Hat package) - addressed in versions 2.2.5-3.el8, 3.2.3-5.el9
pmix - update to 3.2.3-1
pmix-devel - addressed in versions 3.2.3-5, 4.2.6-1
pmix - addressed in versions 3.2.3-5, 4.2.6-1
pmix-mca-params - update to 3.2.3-150300.3.8.1
libpmix2-debuginfo - update to 3.2.3-150300.3.8.1
libmca_common_dstore1-debuginfo - update to 3.2.3-150300.3.8.1
pmix - update to 3.2.3-150300.3.8.1
pmix-plugins - update to 3.2.3-150300.3.8.1
pmix-plugin-munge - update to 3.2.3-150300.3.8.1
pmix-test-debuginfo - update to 3.2.3-150300.3.8.1
pmix-plugins-debuginfo - update to 3.2.3-150300.3.8.1
pmix-headers - update to 3.2.3-150300.3.8.1
pmix-devel - update to 3.2.3-150300.3.8.1
pmix-debugsource - update to 3.2.3-150300.3.8.1
pmix-debuginfo - update to 3.2.3-150300.3.8.1
libmca_common_dstore1 - update to 3.2.3-150300.3.8.1
libpmix2 - update to 3.2.3-150300.3.8.1
pmix-test - update to 3.2.3-150300.3.8.1
pmix-plugin-munge-debuginfo - update to 3.2.3-150300.3.8.1
pmix (Debian package) - addressed in versions 4.0.0-4.1+deb11u1, 4.2.2-1+deb12u1
pmix - addressed in versions 4.1.3-1.fc37, 4.1.3-1.fc38, 4.1.3-1.fc39
pmix-tools - update to 4.2.6-1
pmix-doc - update to 4.2.6-1
pmix-devel - update to 4.2.6-2
pmix-debugsource - update to 4.2.6-2
pmix-debuginfo - update to 4.2.6-2
pmix-tools - update to 4.2.6-2
pmix - update to 4.2.6-2

External References

Related Security Bulletins