CVE-2022-46174
Red Hat Enterprise Linux CoreOS (RHCOS) vulnerability analysis and mitigation

Overview

A race condition vulnerability (CVE-2022-46174) was identified in Amazon EFS Utils versions 1.34.3 and below. The vulnerability was discovered in December 2022 and affects the Amazon Elastic File System (EFS) mount helper component. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to receive NFS connections prior to applying the TLS tunnel (GitHub Advisory).

Technical details

The vulnerability stems from a race condition in the TLS port allocation process. During concurrent mount operations, the mount helper could allocate the same local port for different mount requests before applying the TLS tunnel. This occurs because the port selection process lacked proper synchronization mechanisms. The vulnerability has been assigned a CVSS v3.1 base score of 4.2 (Medium) with the vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L (NVD).

Impact

The race condition can lead to two primary impacts: failed mount operations or inappropriate mapping between an EFS customer's local mount points and their EFS file systems. This could potentially result in mount failures or incorrect file system associations, affecting the reliability and security of EFS mounts (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in efs-utils version 1.34.4. There are no recommended workarounds, and users are strongly advised to update to version 1.34.4 or later to address this security issue. The fix implements a state file mechanism that acts as a TLS port lock file to prevent concurrent port allocation (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Red Hat Enterprise Linux CoreOS (RHCOS) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11561HIGH8.8
  • Rocky LinuxRocky Linux
  • sssd-kcm-debuginfo
NoYesOct 09, 2025
CVE-2025-52565HIGH8.4
  • cAdvisorcAdvisor
  • runc-debuginfo
NoYesNov 06, 2025
CVE-2025-4953HIGH7.4
  • PodmanPodman
  • conmon
NoYesSep 16, 2025
CVE-2025-52881HIGH7.3
  • cAdvisorcAdvisor
  • mesosphere-vsphere-csi
NoYesNov 06, 2025
CVE-2025-31133HIGH7.3
  • cAdvisorcAdvisor
  • crun
NoYesNov 06, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management