Linuxsecurity
Moderate Denial of Service Vulnerability in openSUSE Multipath-Tools
Article Content
A moderate vulnerability (CVE-2026-4051) has been identified in the multipath-tools package of openSUSE, affecting various versions. The vulnerabilities include heap out-of-bounds reads, path traversal issues, and local denial of service (DoS) via blocking IPC send operations. Specifically, issues were reported in the custom format string parser, device-mapper-multipath management, and SCSI PRIN READ FULL STATUS responses. The vulnerabilities could lead to DoS attacks by exhausting connections on the multipathd socket. The update addresses these issues with version 0.9.0+187+suse.5bd6993. Users are advised to apply the patches using SUSE's recommended methods. The vulnerabilities were disclosed on September 7, 2026, and the patch is available immediately. Affected systems include SUSE Linux Enterprise Micro and openSUSE Leap.
Key Points: • openSUSE multipath-tools has a moderate DoS vulnerability (CVE-2026-4051). • The update addresses multiple issues including heap overflows and path traversal. • Users should apply the patch immediately to mitigate potential DoS attacks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.