SUSE-SU-2026:23160-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202623160-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23160-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:23160-1
Published
2026-08-04T11:05:20Z
Modified
2026-08-22T18:23:34Z
Summary
Security update for multipath-tools
Details

This update for multipath-tools fixes the following issues:

Update to version 0.10.7~1+211+suse.18f1559.

Security issues fixed:

  • kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image(bsc#1268145).
  • kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144).

Other updates and bugfixes:

  • Fix system with multipath failing to boot during first boot during the installation (bsc#1232063).
  • Fix code that leads to is_bit_set_in_bitfield: bitfield overflow: 1 >= 0 message showing up in syslog (bsc#1255285).
  • Version 0.10.7~1+211+suse.18f1559:
    • Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ("lba-dependent", "transitioning").
    • Don't set a hardware handler for bio-based multipath devices. The kernel rejects this anyway.
    • Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier.
    • Fix duplicate "checker timed out" log messages when log_checker_err is set to once. (bsc#1254094)
    • Avoid potential buffer overflows in the iet and datacore prioritizers.
    • iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. (gh#opensvc/multipath-tools#145)
  • Version 0.10.6+201+suse.9f189e79:
    • libmultipath: reduce log level of "map X has no targets" (bsc#1257476)
  • Version 0.10.6+200+suse.547788f4 (bsc#1257007):
    • kpartx: fix segfault when operating on regular files (bsc#1257244, bsc#1257153)
    • multipathd: print path offline message even without a checker (bsc#1254094)
    • Fix command descriptions in the multipathd man page.
    • Fix ISO C23 compatibility issue causing errors with new compilers.
    • Fix memory leak caused by not joining the "init unwinder" thread.
    • Fix memory leaks in kpartx.
    • Print the warning "setting scsi timeouts is unsupported for protocol" only once per protocol.
    • Make sure multipath-tools is compiled with the compiler flag -fno-strict-aliasing. (gh#opensvc/multipath-tools#130, bsc#1255285)
  • Version 0.10.5+213+suse.04c3a0ac:
    • Log offline path state if "log_checker_err always" is set
    • mpathpersist: Fix REPORT CAPABILITIES output
  • Version 0.10.5+190+suse.a9f87040:
    • CI: GitHub workflow updates. No code changes.
  • _service: switched to tar_scm for git LFS.
  • Version 0.10.5+125+suse.1ed79487:
    • Fixes from upstream 0.10.5 (see also NEWS.md) (bsc#1253260)
      • Improved the communication with udev and systemd by triggering uevents when path devices are added to or removed from multipath maps, or when multipathd reconfigure is executed after changing blacklist directives in multipath.conf.
      • Failed paths should be checked every polling_interval. In certain cases, this wouldn't happen, because the check interval wasn't reset by multipathd.
      • It could happen that multipathd would accidentally release a SCSI persistent reservation held by another node. Fix it.
      • After manually failing some paths and then reinstating them, sometimes the reinstated paths were immediately failed again by multipathd. Fix it.
      • Various minor fixes reported by coverity.
  • Version 0.10.3+124+suse.ed5b4b11:
    • multipath-tools: add HPE MSA Gen7 (2070/2072) to hwtable (bsc#1246501)
  • Version 0.10.2+123+suse.48d66ee8:
    • multipathd: cli_reinstate(): avoid reinstated paths being failed again (bsc#1244917)
  • Version 0.10.2+122+suse.51e02cc:
    • multipathd: fix hang during shutdown with queuing maps (bsc#1238484).
    • This adds multipathd-queueing.service.
  • Version 0.10.2+117+suse.33411aa:
    • multipathd: trigger uevents for blacklisted paths in reconfigure (bsc#1236321)
    • Make sure maps are reloaded in the path checker loop after detecting an inconsistent or wrong kernel state (bsc#1236392)
    • Make sure udev and systemd notice changes in multipath path state when devices are added to or removed from multipath maps (bsc#1236321)
    • Fix the problem that group_by_tpg might be disabled if one or more paths were offline during initial configuration (bsc#1236392)
    • Fix multipathd crash because of invalid path group index value, for example if an invalid path device was removed from a map. (gh#opensvc/multipath-tools#105, bsc#1236392)
    • Fixed a memory leak in the nvme foreign library.
    • Fixed a problem in the marginal path detection algorithm that could cause the io error check for a recently failed path to be delayed. (bsc#1236390)
    • Reduce log level of harmless "map ... doesn't exist" message
  • Version 0.10.1~2+112+suse.b66763a:
    • libmultipath: reduce log level of "map X has multiple targets" (bsc#1233588)
  • Version 0.10.1~1+113+suse.d6eca5e:
    • This is a pre-release of the upstream stable release 0.10.1.
    • libmultipath: dm_get_maps(): don't bail out for single-map failures (bsc#1233588, gh#opensvc/multipath-tools#102)
    • libmultipath: don't print error message if WATCHDOG_USEC is 0 (bsc#1232227)
    • libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL
    • multipathd: fix deferred_failback_tick for reload removes
  • Version 0.10.0+108+suse.2c2e597:
    • Update fix for bsc#1232063 to upstream-accepted solution
  • Version 0.10.0+106+suse.ffbdb7a:
    • Fix reboot hang if uevent is processed for suspended device (bsc#1232063)
References

Affected packages

SUSE:Linux Micro 6.1 / multipath-tools

Package

Name
multipath-tools
Purl
pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Micro%206.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.10.7~1+211+suse.18f1559-slfo.1.1_1.1

Ecosystem specific

{
    "binaries":  [
        {
            "kpartx":  "0.10.7~1+211+suse.18f1559-slfo.1.1_1.1",
            "libmpath0":  "0.10.7~1+211+suse.18f1559-slfo.1.1_1.1",
            "multipath-tools":  "0.10.7~1+211+suse.18f1559-slfo.1.1_1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23160-1.json"