PT-2026-95575 · Suse · Multipath-Tools

Published

2026-09-08

·

Updated

2026-09-08

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This update for multipath-tools fixes the following issues:
  • Heap Out-of-Bounds Read in Custom Format String Parser via Trailing % (bsc#1277205).
  • Path traversal in device-mapper-multipath failed wwids management (bsc#1277210).
  • SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212).
  • Local Denial of Service via Blocking IPC Send Operations (bsc#1277199).
  • Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209).
  • DoS on multipathd socket by exhausting connections (bsc#1277203).
  • Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208).
Changes for multipath-tools:
  • Update to version 0.7.9+256+suse.60d6bf4.
  • Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

SUSE-SU-2026:4093-1

Affected Products

Multipath-Tools