Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

openSUSE 15.6 Multipath-Tools Moderate Disk Heap Issue Vuln 2026-3184-1

opensuse
Calendar Grey July 22, 2026
Scroller Opensuse
This update for openSUSE addresses two security flaws in multipath-tools, improving system reliability and stability.
An update that has two security fixes can now be installed.

Description

This update for multipath-tools fixes the following issues:

Update to version 0.9.8+292+suse.c0523c1.

* kpartx: integer overflow in the GPT partition table size calculation can

lead to heap OOB read via crafted USB device or disk image(bsc#1268145).

* kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write

via a crafted DASD disk with more than 256 consecutive format labels

(bsc#1268144).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3184=1

Package List

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* multipath-tools-devel-0.9.8+292+suse.c0523c1-150600.3.12.1

* multipath-tools-debugsource-0.9.8+292+suse.c0523c1-150600.3.12.1

* multipath-tools-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1

* multipath-tools-0.9.8+292+suse.c0523c1-150600.3.12.1

* kpartx-0.9.8+292+suse.c0523c1-150600.3.12.1

* libmpath0-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1

* libdmmp0_2_0-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1

* kpartx-debuginfo-0.9.8+292+suse.c0523c1-150600.3.12.1

* libmpath0-0.9.8+292+suse.c0523c1-150600.3.12.1

* libdmmp-devel-0.9.8+292+suse.c0523c1-150600.3.12.1

* libdmmp0_2_0-0.9.8+292+suse.c0523c1-150600.3.12.1

References

* bsc#1268144

* bsc#1268145

## References:

* https://bugzilla.suse.com/show_bug.cgi?id=1268144

* https://bugzilla.suse.com/show_bug.cgi?id=1268145

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3184-1
Release Date: 2026-07-22T07:26:21Z
Affected Products: * openSUSE Leap 15.6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.