{"id":"openSUSE-SU-2026:21802-1","summary":"Security update for multipath-tools","details":"This update for multipath-tools fixes the following issues:\n\n- Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205).\n- Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210).\n- SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212).\n- Local Denial of Service via Blocking IPC Send Operations (bsc#1277199).\n- Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209).\n- DoS on multipathd socket by exhausting connections (bsc#1277203).\n- Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208).\n\nChanges for multipath-tools:\n\n- Update to version 0.12.4+278+suse.9cf9c5c.\n- Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).\n","modified":"2026-09-10T18:23:18.858129653Z","published":"2026-09-07T15:03:57Z","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277199"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277203"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277209"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277210"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277212"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/multipath-tools&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.4+278+suse.9cf9c5c-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libdmmp-devel":"0.12.4+278+suse.9cf9c5c-160000.1.1","libdmmp0_2_0":"0.12.4+278+suse.9cf9c5c-160000.1.1","libmpath0":"0.12.4+278+suse.9cf9c5c-160000.1.1","multipath-tools":"0.12.4+278+suse.9cf9c5c-160000.1.1","multipath-tools-devel":"0.12.4+278+suse.9cf9c5c-160000.1.1","kpartx":"0.12.4+278+suse.9cf9c5c-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21802-1.json"}}],"schema_version":"1.9.0"}