Skip to content
openSUSE Multipath-tools Moderate Denial of Service Vuln 2026-4051

openSUSE Multipath-tools Moderate Denial of Service Vuln 2026-4051

Linuxsecurity LinuxSecurity Advisories September 8, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

## This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.9.0+187+suse.5bd6993. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions:

## This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.9.0+187+suse.5bd6993. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions:

* SUSE Linux Enterprise Micro 5.3

* SUSE Linux Enterprise Micro 5.4

* SUSE Linux Enterprise Micro for Rancher 5.3

* SUSE Linux Enterprise Micro for Rancher 5.4

An update that has seven security fixes can now be installed.

*

*

*

*

*

*

*

Announcement ID: SUSE-SU-2026:4051-1 Release Date: 2026-09-07T15:47:06Z Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases