SUSE-SU-2026:4093-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4093-1
SUSE-SU-2026:4093-1
Summary: Security update for multipath-tools
Details: This update for multipath-tools fixes the following issues: - Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). - Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). - SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). - Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). - Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). - DoS on multipathd socket by exhausting connections (bsc#1277203). - Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: - Update to version 0.7.9+256+suse.60d6bf4. - Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264093-1/, https://bugzilla.suse.com/1277199, https://bugzilla.suse.com/1277203, https://bugzilla.suse.com/1277205, https://bugzilla.suse.com/1277208, https://bugzilla.suse.com/1277209, https://bugzilla.suse.com/1277210, https://bugzilla.suse.com/1277212
Affected packages
Package
Name: multipath-tools
Purl: pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
