{"id":"SUSE-SU-2026:3212-1","summary":"Security update for multipath-tools","details":"This update for multipath-tools fixes the following issues\n\nUpdate to version 0.7.9+238+suse.1249506.\n\n- kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device\n  or disk image(bsc#1268145).\n- kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256\n  consecutive format labels (bsc#1268144).\n","modified":"2026-07-24T17:16:04.967364012Z","published":"2026-07-23T14:13:53Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263212-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268144"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268145"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5","purl":"pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.9+238+suse.1249506-3.20.1"}]}],"ecosystem_specific":{"binaries":[{"kpartx":"0.7.9+238+suse.1249506-3.20.1","multipath-tools":"0.7.9+238+suse.1249506-3.20.1","multipath-tools-devel":"0.7.9+238+suse.1249506-3.20.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3212-1.json"}}],"schema_version":"1.7.5"}