{"id":"AZL-101727","summary":"CVE-2026-89329 affecting package device-mapper-multipath 0.9.6-1","details":"A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.","modified":"2026-09-19T05:33:49Z","published":"2026-09-11T19:17:47Z","upstream":["CVE-2026-89329"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89329"}],"affected":[{"package":{"name":"device-mapper-multipath","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/device-mapper-multipath"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.9.6-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101727.json"}}],"schema_version":"1.9.0"}