Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

SUSE Multipath-Tools Moderate DASD Unbounded Array Write Vuln 2026-3184-1

suse
Calendar Grey July 22, 2026
Scroller Suse
Critical security fixes for multipath-tools update on openSUSE Leap 15.6 addressing integer overflow and bounds issues, install recommended.
SUSE released a moderate security update for multipath-tools on openSUSE Leap 15.6, addressing integer overflow and bounds check issues that could lead to potential vulnerabilities...

Summary

## This update for multipath-tools fixes the following issues: Update to version 0.9.8+292+suse.c0523c1. * kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image(bsc#1268145). * kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3184=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * multipath-tools-devel-0.9.8+292+suse.c0523c1-150600.3.12.1

References

* bsc#1268144

* bsc#1268145

Affected Products:

* openSUSE Leap 15.6

An update that has two security fixes can now be installed.

##

* https://bugzilla.suse.com/show_bug.cgi?id=1268144

* https://bugzilla.suse.com/show_bug.cgi?id=1268145

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3184-1
Release Date: 2026-07-22T07:26:21Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.