Moderate Denial of Service Vulnerability in openSUSE Multipath-Tools

Moderate Denial of Service Vulnerability in openSUSE Multipath-Tools

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A moderate vulnerability (CVE-2026-4051) has been identified in the multipath-tools package of openSUSE, affecting various versions. The vulnerabilities include heap out-of-bounds reads, path traversal issues, and local denial of service (DoS) via blocking IPC send operations. Specifically, issues were reported in the custom format string parser, device-mapper-multipath management, and SCSI PRIN READ FULL STATUS responses. The vulnerabilities could lead to DoS attacks by exhausting connections on the multipathd socket. The update addresses these issues with version 0.9.0+187+suse.5bd6993. Users are advised to apply the patches using SUSE's recommended methods. The vulnerabilities were disclosed on September 7, 2026, and the patch is available immediately. Affected systems include SUSE Linux Enterprise Micro and openSUSE Leap.

Key Points: • openSUSE multipath-tools has a moderate DoS vulnerability (CVE-2026-4051). • The update addresses multiple issues including heap overflows and path traversal. • Users should apply the patch immediately to mitigate potential DoS attacks.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-4051 disclosed
The vulnerability affecting multipath-tools was announced with multiple security issues identified.
Linuxsecurity
2026-09-07
Patch released
SUSE released version 0.9.0+187+suse.5bd6993 to address the identified vulnerabilities.
Linuxsecurity