{"id":"SUSE-SU-2026:3199-1","summary":"Security update for multipath-tools","details":"This update for multipath-tools fixes the following issues\n\n- kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device\n  or disk image(bsc#1268145).\n- kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256\n  consecutive format labels (bsc#1268144).\n","modified":"2026-07-23T09:45:06.881742605Z","published":"2026-07-22T18:46:42Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263199-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268144"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268145"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0+168+suse.54b6b26-150400.4.22.1"}]}],"ecosystem_specific":{"binaries":[{"libmpath0":"0.9.0+168+suse.54b6b26-150400.4.22.1","multipath-tools":"0.9.0+168+suse.54b6b26-150400.4.22.1","kpartx":"0.9.0+168+suse.54b6b26-150400.4.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3199-1.json"}},{"package":{"name":"multipath-tools","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0+168+suse.54b6b26-150400.4.22.1"}]}],"ecosystem_specific":{"binaries":[{"multipath-tools":"0.9.0+168+suse.54b6b26-150400.4.22.1","kpartx":"0.9.0+168+suse.54b6b26-150400.4.22.1","libmpath0":"0.9.0+168+suse.54b6b26-150400.4.22.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3199-1.json"}}],"schema_version":"1.7.5"}