SUSE-SU-2026:23160-1: critical: Security update for multipath-tools
SLE-UPDATES
null at suse.de
Fri Aug 21 16:41:42 UTC 2026
# Security update for multipath-tools
Announcement ID: SUSE-SU-2026:23160-1
Release Date: 2026-08-04T11:04:57Z
Rating: critical
References:
* bsc#1232063
* bsc#1232227
* bsc#1233588
* bsc#1236321
* bsc#1236390
* bsc#1236392
* bsc#1238484
* bsc#1244917
* bsc#1246501
* bsc#1253260
* bsc#1254094
* bsc#1255285
* bsc#1257007
* bsc#1257153
* bsc#1257244
* bsc#1257476
* bsc#1268144
* bsc#1268145
Affected Products:
* SUSE Linux Micro 6.1
An update that has 18 fixes can now be installed.
## Description:
This update for multipath-tools fixes the following issues:
Update to version 0.10.7~1+211+suse.18f1559.
Security issues fixed:
* kpartx: integer overflow in the GPT partition table size calculation can
lead to heap OOB read via crafted USB device or disk image(bsc#1268145).
* kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write
via a crafted DASD disk with more than 256 consecutive format labels
(bsc#1268144).
Other updates and bugfixes:
* Fix system with multipath failing to boot during first boot during the
installation (bsc#1232063).
* Fix code that leads to `is_bit_set_in_bitfield: bitfield overflow: 1 >=
0` message showing up in syslog (bsc#1255285).
* Version 0.10.7~1+211+suse.18f1559:
* Fix ALUA asymmetric access state descriptions in multipathd logs, so that
the same terms are used as by the kernel ("lba-dependent", "transitioning").
* Don't set a hardware handler for bio-based multipath devices. The kernel
rejects this anyway.
* Fix WWID detection for legacy devices that use the older SCSI-2 VPD page
0x83 format for their device identifier.
* Fix duplicate "checker timed out" log messages when `log_checker_err` is set
to `once`. (bsc#1254094)
* Avoid potential buffer overflows in the iet and datacore prioritizers.
* iet prioritizer: avoid misleading error message with systemd 256 and newer,
and properly use udev to derive path parameters. (gh#opensvc/multipath-
tools#145)
* Version 0.10.6+201+suse.9f189e79:
* libmultipath: reduce log level of "map X has no targets" (bsc#1257476)
* Version 0.10.6+200+suse.547788f4 (bsc#1257007):
* kpartx: fix segfault when operating on regular files (bsc#1257244,
bsc#1257153)
* multipathd: print path offline message even without a checker (bsc#1254094)
* Fix command descriptions in the multipathd man page.
* Fix ISO C23 compatibility issue causing errors with new compilers.
* Fix memory leak caused by not joining the "init unwinder" thread.
* Fix memory leaks in kpartx.
* Print the warning "setting scsi timeouts is unsupported for protocol" only
once per protocol.
* Make sure multipath-tools is compiled with the compiler flag `-fno-strict-
aliasing`. (gh#opensvc/multipath-tools#130, bsc#1255285)
* Version 0.10.5+213+suse.04c3a0ac:
* Log offline path state if "log_checker_err always" is set
* mpathpersist: Fix REPORT CAPABILITIES output
* Version 0.10.5+190+suse.a9f87040:
* CI: GitHub workflow updates. No code changes.
* _service: switched to tar_scm for git LFS.
* Version 0.10.5+125+suse.1ed79487:
* Fixes from upstream 0.10.5 (see also NEWS.md) (bsc#1253260)
* Improved the communication with **udev** and **systemd** by triggering uevents when path devices are added to or removed from multipath maps, or when `multipathd reconfigure` is executed after changing blacklist directives in `multipath.conf`.
* Failed paths should be checked every `polling_interval`. In certain cases, this wouldn't happen, because the check interval wasn't reset by multipathd.
* It could happen that multipathd would accidentally release a SCSI persistent reservation held by another node. Fix it.
* After manually failing some paths and then reinstating them, sometimes the reinstated paths were immediately failed again by multipathd. Fix it.
* Various minor fixes reported by coverity.
* Version 0.10.3+124+suse.ed5b4b11:
* multipath-tools: add HPE MSA Gen7 (2070/2072) to hwtable (bsc#1246501)
* Version 0.10.2+123+suse.48d66ee8:
* multipathd: cli_reinstate(): avoid reinstated paths being failed again
(bsc#1244917)
* Version 0.10.2+122+suse.51e02cc:
* multipathd: fix hang during shutdown with queuing maps (bsc#1238484).
* This adds multipathd-queueing.service.
* Version 0.10.2+117+suse.33411aa:
* multipathd: trigger uevents for blacklisted paths in reconfigure
(bsc#1236321)
* Make sure maps are reloaded in the path checker loop after detecting an
inconsistent or wrong kernel state (bsc#1236392)
* Make sure udev and systemd notice changes in multipath path state when
devices are added to or removed from multipath maps (bsc#1236321)
* Fix the problem that `group_by_tpg` might be disabled if one or more paths
were offline during initial configuration (bsc#1236392)
* Fix multipathd crash because of invalid path group index value, for example
if an invalid path device was removed from a map. (gh#opensvc/multipath-
tools#105, bsc#1236392)
* Fixed a memory leak in the nvme foreign library.
* Fixed a problem in the marginal path detection algorithm that could cause
the io error check for a recently failed path to be delayed. (bsc#1236390)
* Reduce log level of harmless "map ... doesn't exist" message
* Version 0.10.1~2+112+suse.b66763a:
* libmultipath: reduce log level of "map X has multiple targets" (bsc#1233588)
* Version 0.10.1~1+113+suse.d6eca5e:
* This is a pre-release of the upstream stable release 0.10.1.
* libmultipath: dm_get_maps(): don't bail out for single-map failures
(bsc#1233588, gh#opensvc/multipath-tools#102)
* libmultipath: don't print error message if WATCHDOG_USEC is 0 (bsc#1232227)
* libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL
* multipathd: fix deferred_failback_tick for reload removes
* Version 0.10.0+108+suse.2c2e597:
* Update fix for bsc#1232063 to upstream-accepted solution
* Version 0.10.0+106+suse.ffbdb7a:
* Fix reboot hang if uevent is processed for suspended device (bsc#1232063)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Micro 6.1
zypper in -t patch SUSE-SLE-Micro-6.1-652=1
## Package List:
* SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64)
* multipath-tools-debuginfo-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
* kpartx-debuginfo-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
* multipath-tools-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
* libmpath0-debuginfo-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
* kpartx-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
* libmpath0-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
* multipath-tools-debugsource-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
## References:
* https://bugzilla.suse.com/show_bug.cgi?id=1232063
* https://bugzilla.suse.com/show_bug.cgi?id=1232227
* https://bugzilla.suse.com/show_bug.cgi?id=1233588
* https://bugzilla.suse.com/show_bug.cgi?id=1236321
* https://bugzilla.suse.com/show_bug.cgi?id=1236390
* https://bugzilla.suse.com/show_bug.cgi?id=1236392
* https://bugzilla.suse.com/show_bug.cgi?id=1238484
* https://bugzilla.suse.com/show_bug.cgi?id=1244917
* https://bugzilla.suse.com/show_bug.cgi?id=1246501
* https://bugzilla.suse.com/show_bug.cgi?id=1253260
* https://bugzilla.suse.com/show_bug.cgi?id=1254094
* https://bugzilla.suse.com/show_bug.cgi?id=1255285
* https://bugzilla.suse.com/show_bug.cgi?id=1257007
* https://bugzilla.suse.com/show_bug.cgi?id=1257153
* https://bugzilla.suse.com/show_bug.cgi?id=1257244
* https://bugzilla.suse.com/show_bug.cgi?id=1257476
* https://bugzilla.suse.com/show_bug.cgi?id=1268144
* https://bugzilla.suse.com/show_bug.cgi?id=1268145
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260821/308089fb/attachment.htm>
More information about the sle-updates
mailing list