Description
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Published: 2026-09-11
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Denial of Service
Action: Apply Workaround
AI Analysis

Impact

The vulnerability resides in the multipathd daemon used by device‑mapper‑multipath. A local attacker who can reach the Unix control socket may issue valid commands and then stop reading the replies. This forces the multipathd listener thread to block, causing legitimate inter-process communication to hang or time out. The flaw does not lead to privilege escalation, arbitrary code execution, or compromise of data confidentiality or integrity, but leads to a local denial of service.

Affected Systems

Affected systems include Red Hat Enterprise Linux 6 through 10 and Red Hat OpenShift Container Platform 4, where the multipathd IPC socket is world‑writable and thus exploitable by any local user who has permission to connect to the socket.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. An EPSS score of less than 1 % suggests a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However any user with access to the multipathd control socket on an affected system can trigger the denial of service, making the risk significant for those environments.

Generated by OpenCVE AI on September 21, 2026 at 04:07 UTC.

Remediation

Vendor Workaround

To mitigate this issue, implement strict local access controls on systems running `multipathd`. This limits the ability of unprivileged users to interact with the `multipathd` IPC socket, thereby preventing exploitation of the world-writable control socket. Ensure that only trusted administrators have local access to the system.


OpenCVE Recommended Actions

  • Restrict access to the multipathd IPC socket to trusted administrators by removing world‑writable permissions, effectively implementing the provided workaround.
  • If device‑mapper‑multipath functionality is not required, disable the multipathd service to reduce the attack surface.
  • Audit local user accounts to ensure only privileged control socket, enforcing appropriate filesystem permissions or SELinux rules.

Generated by OpenCVE AI on September 21, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Container Platform
Vendors & Products Redhat openshift Container Platform

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Title Device-mapper-multipath: local denial of service via blocking ipc send operations
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-1322
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Redhat Enterprise Linux Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T19:35:24.509Z

Reserved: 2026-09-11T15:06:03.354Z

Link: CVE-2026-89329

cve-icon Vulnrichment

Updated: 2026-09-11T19:35:17.175Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T19:17:47.710

Modified: 2026-09-16T19:42:43.623

Link: CVE-2026-89329

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T15:10:00Z

Links: CVE-2026-89329 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:15:08Z

Weaknesses
  • CWE-1322

    Use of Blocking Code in Single-threaded, Non-blocking Context