openSUSE-SU-2026:21802-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21802-1
openSUSE-SU-2026:21802-1
Summary: Security update for multipath-tools
Details: This update for multipath-tools fixes the following issues: - Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). - Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). - SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). - Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). - Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). - DoS on multipathd socket by exhausting connections (bsc#1277203). - Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: - Update to version 0.12.4+278+suse.9cf9c5c. - Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).
References: , https://bugzilla.suse.com/1277199, https://bugzilla.suse.com/1277203, https://bugzilla.suse.com/1277205, https://bugzilla.suse.com/1277208, https://bugzilla.suse.com/1277209, https://bugzilla.suse.com/1277210, https://bugzilla.suse.com/1277212
Affected packages
Package
Name: multipath-tools
Purl: pkg:rpm/opensuse/multipath-tools&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
