{"id":"UBUNTU-CVE-2026-89329","details":"A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.","modified":"2026-09-16T11:43:12Z","published":"2026-09-11T19:17:00Z","upstream":["CVE-2026-89329"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-89329"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-89329"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2470013"},{"type":"REPORT","url":"https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-89329"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.4.9-3ubuntu7","0.4.9-3ubuntu7.2","0.4.9-3ubuntu7.4","0.4.9-3ubuntu7.6","0.4.9-3ubuntu7.7","0.4.9-3ubuntu7.9","0.4.9-3ubuntu7.11","0.4.9-3ubuntu7.12","0.4.9-3ubuntu7.13","0.4.9-3ubuntu7.14","0.4.9-3ubuntu7.15","0.4.9-3ubuntu7.16"],"ecosystem_specific":{"binaries":[{"binary_name":"kpartx","binary_version":"0.4.9-3ubuntu7.16"},{"binary_name":"kpartx-boot","binary_version":"0.4.9-3ubuntu7.16"},{"binary_name":"multipath-tools","binary_version":"0.4.9-3ubuntu7.16"},{"binary_version":"0.4.9-3ubuntu7.16","binary_name":"multipath-tools-boot"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}},{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.5.0-7ubuntu7","0.5.0-7ubuntu8","0.5.0-7ubuntu9","0.5.0-7ubuntu10","0.5.0-7ubuntu11","0.5.0-7ubuntu12","0.5.0-7ubuntu14","0.5.0-7ubuntu15","0.5.0-7ubuntu16","0.5.0+git1.656f8865-5ubuntu1","0.5.0+git1.656f8865-5ubuntu2","0.5.0+git1.656f8865-5ubuntu2.1","0.5.0+git1.656f8865-5ubuntu2.2","0.5.0+git1.656f8865-5ubuntu2.3","0.5.0+git1.656f8865-5ubuntu2.4","0.5.0+git1.656f8865-5ubuntu2.5"],"ecosystem_specific":{"binaries":[{"binary_name":"kpartx","binary_version":"0.5.0+git1.656f8865-5ubuntu2.5"},{"binary_version":"0.5.0+git1.656f8865-5ubuntu2.5","binary_name":"kpartx-boot"},{"binary_name":"multipath-tools","binary_version":"0.5.0+git1.656f8865-5ubuntu2.5"},{"binary_version":"0.5.0+git1.656f8865-5ubuntu2.5","binary_name":"multipath-tools-boot"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}},{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.4-5ubuntu1","0.7.4-2ubuntu1","0.7.4-2ubuntu3","0.7.4-2ubuntu3.1","0.7.4-2ubuntu3.2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.7.4-2ubuntu3.2","binary_name":"kpartx"},{"binary_name":"kpartx-boot","binary_version":"0.7.4-2ubuntu3.2"},{"binary_name":"multipath-tools","binary_version":"0.7.4-2ubuntu3.2"},{"binary_name":"multipath-tools-boot","binary_version":"0.7.4-2ubuntu3.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}},{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.7.9-3ubuntu6","0.7.9-3ubuntu7","0.8.3-1ubuntu1","0.8.3-1ubuntu2","0.8.3-1ubuntu2.1","0.8.3-1ubuntu2.2","0.8.3-1ubuntu2.3","0.8.3-1ubuntu2.4"],"ecosystem_specific":{"binaries":[{"binary_name":"kpartx","binary_version":"0.8.3-1ubuntu2.4"},{"binary_name":"kpartx-boot","binary_version":"0.8.3-1ubuntu2.4"},{"binary_version":"0.8.3-1ubuntu2.4","binary_name":"multipath-tools"},{"binary_name":"multipath-tools-boot","binary_version":"0.8.3-1ubuntu2.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}},{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.5-2ubuntu2","0.8.5-2ubuntu3","0.8.8-1ubuntu1","0.8.8-1ubuntu1.22.04.1","0.8.8-1ubuntu1.22.04.3","0.8.8-1ubuntu1.22.04.4"],"ecosystem_specific":{"binaries":[{"binary_version":"0.8.8-1ubuntu1.22.04.4","binary_name":"kpartx"},{"binary_name":"kpartx-boot","binary_version":"0.8.8-1ubuntu1.22.04.4"},{"binary_name":"multipath-tools","binary_version":"0.8.8-1ubuntu1.22.04.4"},{"binary_name":"multipath-tools-boot","binary_version":"0.8.8-1ubuntu1.22.04.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}},{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.4-5ubuntu3","0.9.4-5ubuntu6","0.9.4-5ubuntu7","0.9.4-5ubuntu8","0.9.4-5ubuntu8.1","0.9.4-5ubuntu8.2"],"ecosystem_specific":{"binaries":[{"binary_name":"kpartx","binary_version":"0.9.4-5ubuntu8.2"},{"binary_version":"0.9.4-5ubuntu8.2","binary_name":"kpartx-boot"},{"binary_name":"multipath-tools","binary_version":"0.9.4-5ubuntu8.2"},{"binary_version":"0.9.4-5ubuntu8.2","binary_name":"multipath-tools-boot"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}},{"package":{"name":"multipath-tools","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/multipath-tools?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.1-3ubuntu2","0.12.0-1ubuntu1","0.12.0-1ubuntu2","0.12.0-1ubuntu3","0.14.3-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"kpartx","binary_version":"0.14.3-2ubuntu1"},{"binary_version":"0.14.3-2ubuntu1","binary_name":"libmpathcmd0"},{"binary_version":"0.14.3-2ubuntu1","binary_name":"libmpathpersist0"},{"binary_name":"libmpathvalid0","binary_version":"0.14.3-2ubuntu1"},{"binary_version":"0.14.3-2ubuntu1","binary_name":"libmultipath0"},{"binary_name":"multipath-tools","binary_version":"0.14.3-2ubuntu1"},{"binary_name":"multipath-tools-boot","binary_version":"0.14.3-2ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89329.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}