Description
A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Published: 2026-09-11
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

To mitigate this issue, implement strict local access controls on systems running `multipathd`. This limits the ability of unprivileged users to interact with the `multipathd` IPC socket, thereby preventing exploitation of the world-writable control socket. Ensure that only trusted administrators have local access to the system.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Title Device-mapper-multipath: local denial of service via blocking ipc send operations
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-1322
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-11T19:35:24.509Z

Reserved: 2026-09-11T15:06:03.354Z

Link: CVE-2026-89329

cve-icon Vulnrichment

Updated: 2026-09-11T19:35:17.175Z

cve-icon NVD

Status : Received

Published: 2026-09-11T19:17:47.710

Modified: 2026-09-11T20:19:23.543

Link: CVE-2026-89329

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T15:10:00Z

Links: CVE-2026-89329 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses