Impact
The vulnerability resides in the multipathd daemon used by device‑mapper‑multipath. A local attacker who can reach the Unix control socket may issue valid commands and then stop reading the replies. This forces the multipathd listener thread to block, causing legitimate inter-process communication to hang or time out. The flaw does not lead to privilege escalation, arbitrary code execution, or compromise of data confidentiality or integrity, but leads to a local denial of service.
Affected Systems
Affected systems include Red Hat Enterprise Linux 6 through 10 and Red Hat OpenShift Container Platform 4, where the multipathd IPC socket is world‑writable and thus exploitable by any local user who has permission to connect to the socket.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity. An EPSS score of less than 1 % suggests a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However any user with access to the multipathd control socket on an affected system can trigger the denial of service, making the risk significant for those environments.
OpenCVE Enrichment