OESA-2026-4158

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-4158
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-4158.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-4158
Upstream
  • CVE-2026-89329
Published
2026-09-30T13:47:09Z
Modified
2026-10-01T02:00:04Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
multipath-tools security update
Details

This package provides the multipath tool and the multipathd daemon to manage dm-multipath devices. multipath can detect and set up multipath maps. multipathd sets up multipath maps automatically, monitors path devices for failure, removal, or addition, and applies the necessary changes to the multipath maps to ensure continuous availability of the map devices.

Security Fix(es):

A flaw was found in multipathd. A local attacker with access to the multipathd UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the multipathd listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.(CVE-2026-89329)

Database specific
{
    "severity":  "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / multipath-tools

Package

Name
multipath-tools
Purl
pkg:rpm/openEuler/multipath-tools&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.7-29.oe2203sp4

Ecosystem specific

{
    "aarch64":  [
        "kpartx-0.8.7-29.oe2203sp4.aarch64.rpm",
        "multipath-tools-0.8.7-29.oe2203sp4.aarch64.rpm",
        "multipath-tools-debuginfo-0.8.7-29.oe2203sp4.aarch64.rpm",
        "multipath-tools-debugsource-0.8.7-29.oe2203sp4.aarch64.rpm",
        "multipath-tools-devel-0.8.7-29.oe2203sp4.aarch64.rpm"
    ],
    "noarch":  [
        "multipath-tools-help-0.8.7-29.oe2203sp4.noarch.rpm"
    ],
    "src":  [
        "multipath-tools-0.8.7-29.oe2203sp4.src.rpm"
    ],
    "x86_64":  [
        "kpartx-0.8.7-29.oe2203sp4.x86_64.rpm",
        "multipath-tools-0.8.7-29.oe2203sp4.x86_64.rpm",
        "multipath-tools-debuginfo-0.8.7-29.oe2203sp4.x86_64.rpm",
        "multipath-tools-debugsource-0.8.7-29.oe2203sp4.x86_64.rpm",
        "multipath-tools-devel-0.8.7-29.oe2203sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-4158.json"