On Mon, 2026-07-06 at 20:48 -0400, Benjamin Marzinski wrote: > In the iet and datacore prioritizers, multipath was using sscanf to > get > a string for a 255 byte buffer, without limiting the size of the > string. > This could result in a buffer overflow, if there was a bad value in > multipath.conf. > > Signed-off-by: Benjamin Marzinski <[email protected]> > --- > > Note: > This patch applies on top of Martin's ("libmultipath: iet > prioritizer: > obtain PATH_ID from udev") commit, from the "tip" branch.
As that patch hasn't been verified yet, I'm going to apply your patch on the "queue" branch for now. Regards Martin -- Dr. Martin Wilck <[email protected]> SUSE Software Solutions Germany GmbH, Frankenstr. 146, 90461 Nürnberg, Germany Geschäftsführer: Jochen Jaser, Andrew McDonald (HRB 36809,AG Nürnberg)
