{"id":"SUSE-SU-2026:4064-1","summary":"Security update for multipath-tools","details":"This update for multipath-tools fixes the following issues:\n\n- Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205).\n- Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210).\n- SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212).\n- Local Denial of Service via Blocking IPC Send Operations (bsc#1277199).\n- Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209).\n- DoS on multipathd socket by exhausting connections (bsc#1277203).\n- Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208).\n\nChanges for multipath-tools:\n\n- Update to version 0.9.4+153+suse.eec9ef1.\n- Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).\n","modified":"2026-09-13T18:23:19.457417252Z","published":"2026-09-08T07:02:47Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264064-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277199"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277203"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277209"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277210"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277212"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"SUSE:Linux Enterprise Micro 5.5","purl":"pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Enterprise%20Micro%205.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.4+153+suse.eec9ef1-150500.3.15.1"}]}],"ecosystem_specific":{"binaries":[{"kpartx":"0.9.4+153+suse.eec9ef1-150500.3.15.1","libmpath0":"0.9.4+153+suse.eec9ef1-150500.3.15.1","multipath-tools":"0.9.4+153+suse.eec9ef1-150500.3.15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4064-1.json"}}],"schema_version":"1.9.0"}