SUSE-SU-2026:23160-1: critical: Security update for multipath-tools

SLE-UPDATES null at suse.de
Fri Aug 21 16:41:42 UTC 2026


# Security update for multipath-tools

Announcement ID: SUSE-SU-2026:23160-1  
Release Date: 2026-08-04T11:04:57Z  
Rating: critical  
References:

  * bsc#1232063
  * bsc#1232227
  * bsc#1233588
  * bsc#1236321
  * bsc#1236390
  * bsc#1236392
  * bsc#1238484
  * bsc#1244917
  * bsc#1246501
  * bsc#1253260
  * bsc#1254094
  * bsc#1255285
  * bsc#1257007
  * bsc#1257153
  * bsc#1257244
  * bsc#1257476
  * bsc#1268144
  * bsc#1268145

  
Affected Products:

  * SUSE Linux Micro 6.1

  
  
An update that has 18 fixes can now be installed.

## Description:

This update for multipath-tools fixes the following issues:

Update to version 0.10.7~1+211+suse.18f1559.

Security issues fixed:

  * kpartx: integer overflow in the GPT partition table size calculation can
    lead to heap OOB read via crafted USB device or disk image(bsc#1268145).
  * kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write
    via a crafted DASD disk with more than 256 consecutive format labels
    (bsc#1268144).

Other updates and bugfixes:

  * Fix system with multipath failing to boot during first boot during the
    installation (bsc#1232063).
  * Fix code that leads to `is_bit_set_in_bitfield: bitfield overflow: 1 >=
    0` message showing up in syslog (bsc#1255285).
  * Version 0.10.7~1+211+suse.18f1559:
  * Fix ALUA asymmetric access state descriptions in multipathd logs, so that
    the same terms are used as by the kernel ("lba-dependent", "transitioning").
  * Don't set a hardware handler for bio-based multipath devices. The kernel
    rejects this anyway.
  * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page
    0x83 format for their device identifier.
  * Fix duplicate "checker timed out" log messages when `log_checker_err` is set
    to `once`. (bsc#1254094)
  * Avoid potential buffer overflows in the iet and datacore prioritizers.
  * iet prioritizer: avoid misleading error message with systemd 256 and newer,
    and properly use udev to derive path parameters. (gh#opensvc/multipath-
    tools#145)
  * Version 0.10.6+201+suse.9f189e79:
  * libmultipath: reduce log level of "map X has no targets" (bsc#1257476)
  * Version 0.10.6+200+suse.547788f4 (bsc#1257007):
  * kpartx: fix segfault when operating on regular files (bsc#1257244,
    bsc#1257153)
  * multipathd: print path offline message even without a checker (bsc#1254094)
  * Fix command descriptions in the multipathd man page.
  * Fix ISO C23 compatibility issue causing errors with new compilers.
  * Fix memory leak caused by not joining the "init unwinder" thread.
  * Fix memory leaks in kpartx.
  * Print the warning "setting scsi timeouts is unsupported for protocol" only
    once per protocol.
  * Make sure multipath-tools is compiled with the compiler flag `-fno-strict-
    aliasing`. (gh#opensvc/multipath-tools#130, bsc#1255285)
  * Version 0.10.5+213+suse.04c3a0ac:
  * Log offline path state if "log_checker_err always" is set
  * mpathpersist: Fix REPORT CAPABILITIES output
  * Version 0.10.5+190+suse.a9f87040:
  * CI: GitHub workflow updates. No code changes.
  * _service: switched to tar_scm for git LFS.
  * Version 0.10.5+125+suse.1ed79487:
  * Fixes from upstream 0.10.5 (see also NEWS.md) (bsc#1253260)
    * Improved the communication with **udev** and **systemd** by triggering uevents when path devices are added to or removed from multipath maps, or when `multipathd reconfigure` is executed after changing blacklist directives in `multipath.conf`.
    * Failed paths should be checked every `polling_interval`. In certain cases, this wouldn't happen, because the check interval wasn't reset by multipathd.
    * It could happen that multipathd would accidentally release a SCSI persistent reservation held by another node. Fix it.
    * After manually failing some paths and then reinstating them, sometimes the reinstated paths were immediately failed again by multipathd. Fix it.
    * Various minor fixes reported by coverity.
  * Version 0.10.3+124+suse.ed5b4b11:
  * multipath-tools: add HPE MSA Gen7 (2070/2072) to hwtable (bsc#1246501)
  * Version 0.10.2+123+suse.48d66ee8:
  * multipathd: cli_reinstate(): avoid reinstated paths being failed again
    (bsc#1244917)
  * Version 0.10.2+122+suse.51e02cc:
  * multipathd: fix hang during shutdown with queuing maps (bsc#1238484).
  * This adds multipathd-queueing.service.
  * Version 0.10.2+117+suse.33411aa:
  * multipathd: trigger uevents for blacklisted paths in reconfigure
    (bsc#1236321)
  * Make sure maps are reloaded in the path checker loop after detecting an
    inconsistent or wrong kernel state (bsc#1236392)
  * Make sure udev and systemd notice changes in multipath path state when
    devices are added to or removed from multipath maps (bsc#1236321)
  * Fix the problem that `group_by_tpg` might be disabled if one or more paths
    were offline during initial configuration (bsc#1236392)
  * Fix multipathd crash because of invalid path group index value, for example
    if an invalid path device was removed from a map. (gh#opensvc/multipath-
    tools#105, bsc#1236392)
  * Fixed a memory leak in the nvme foreign library.
  * Fixed a problem in the marginal path detection algorithm that could cause
    the io error check for a recently failed path to be delayed. (bsc#1236390)
  * Reduce log level of harmless "map ... doesn't exist" message
  * Version 0.10.1~2+112+suse.b66763a:
  * libmultipath: reduce log level of "map X has multiple targets" (bsc#1233588)
  * Version 0.10.1~1+113+suse.d6eca5e:
  * This is a pre-release of the upstream stable release 0.10.1.
  * libmultipath: dm_get_maps(): don't bail out for single-map failures
    (bsc#1233588, gh#opensvc/multipath-tools#102)
  * libmultipath: don't print error message if WATCHDOG_USEC is 0 (bsc#1232227)
  * libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL
  * multipathd: fix deferred_failback_tick for reload removes
  * Version 0.10.0+108+suse.2c2e597:
  * Update fix for bsc#1232063 to upstream-accepted solution
  * Version 0.10.0+106+suse.ffbdb7a:
  * Fix reboot hang if uevent is processed for suspended device (bsc#1232063)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Micro 6.1  
    zypper in -t patch SUSE-SLE-Micro-6.1-652=1

## Package List:

  * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64)
    * multipath-tools-debuginfo-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
    * kpartx-debuginfo-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
    * multipath-tools-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
    * libmpath0-debuginfo-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
    * kpartx-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
    * libmpath0-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1
    * multipath-tools-debugsource-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1232063
  * https://bugzilla.suse.com/show_bug.cgi?id=1232227
  * https://bugzilla.suse.com/show_bug.cgi?id=1233588
  * https://bugzilla.suse.com/show_bug.cgi?id=1236321
  * https://bugzilla.suse.com/show_bug.cgi?id=1236390
  * https://bugzilla.suse.com/show_bug.cgi?id=1236392
  * https://bugzilla.suse.com/show_bug.cgi?id=1238484
  * https://bugzilla.suse.com/show_bug.cgi?id=1244917
  * https://bugzilla.suse.com/show_bug.cgi?id=1246501
  * https://bugzilla.suse.com/show_bug.cgi?id=1253260
  * https://bugzilla.suse.com/show_bug.cgi?id=1254094
  * https://bugzilla.suse.com/show_bug.cgi?id=1255285
  * https://bugzilla.suse.com/show_bug.cgi?id=1257007
  * https://bugzilla.suse.com/show_bug.cgi?id=1257153
  * https://bugzilla.suse.com/show_bug.cgi?id=1257244
  * https://bugzilla.suse.com/show_bug.cgi?id=1257476
  * https://bugzilla.suse.com/show_bug.cgi?id=1268144
  * https://bugzilla.suse.com/show_bug.cgi?id=1268145

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260821/308089fb/attachment.htm>


More information about the sle-updates mailing list