{"id":"SUSE-SU-2026:3489-1","summary":"Security update for multipath-tools","details":"This update for multipath-tools fixes the following issues:\n\nUpdate to version 0.9.4+134+suse.c82f347.\n  \n- kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device\n  or disk image (bsc#1268145).\n- kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256\n  consecutive format labels (bsc#1268144).\n","modified":"2026-08-04T18:30:05.185590460Z","published":"2026-08-04T11:57:09Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263489-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268144"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268145"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"SUSE:Linux Enterprise Micro 5.5","purl":"pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.4+134+suse.c82f347-150500.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"kpartx":"0.9.4+134+suse.c82f347-150500.3.12.1","libmpath0":"0.9.4+134+suse.c82f347-150500.3.12.1","multipath-tools":"0.9.4+134+suse.c82f347-150500.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3489-1.json"}}],"schema_version":"1.8.0"}