{"id":"SUSE-SU-2026:23054-1","summary":"Security update for multipath-tools","details":"This update for multipath-tools fixes the following issues:\n\nUpdate to version 0.9.8+292+suse.c0523c1.\n\nSecurity issues fixed:\n\n- kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device\n  or disk image(bsc#1268145).\n- kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256\n  consecutive format labels (bsc#1268144).\n\nOther updates and bugfixes:\n\n- [Build 32.2] System with multipath fails to boot  during first boot during the installation (bsc#1232063).\n- [Build 50.1] multipath btrfs i/o error on both Leap 15.6 and SLES 15 SP6 (bsc#1219289).\n- Fix code that leads to `is_bit_set_in_bitfield: bitfield overflow: 1 \u003e= 0` message showing up in syslog\n  (bsc#1255285).\n- Version 0.9.8+266+suse.53479977 (bsc#1257007):\n  * kpartx: fix segfault when operating on regular files (bsc#1257244, bsc#1257153)\n  * multipathd: print path offline message even without a checker (bsc#1254094)\n  * Fix command descriptions in the multipathd man page.\n  * Fix ISO C23 compatibility issue causing errors with new compilers.\n  * Fix memory leak caused by not joining the \"init unwinder\" thread.\n  * Fix memory leaks in kpartx.\n  * Print the warning \"setting scsi timeouts is unsupported for protocol\" only once per protocol.\n  * Make sure multipath-tools is compiled with the compiler flag `-fno-strict-aliasing`.\n    (gh#opensvc/multipath-tools#130, bsc#1255285)\n- Version 0.9.8+247+suse.863ae86f:\n  * Log offline path state if \"log_checker_err always\" is set\n- Version 0.9.8+246+suse.fb81edd2:\n  * CI: GitHub workflow updates. No code changes.\n- Version 0.9.8+166+suse.95399ce1:\n  - Backported fixes from upstream 0.9.9 ... 0.10.5 (bsc#1253260)\n    * Updates to the built-in hardware table:\n      - add some NVMe storage array (VASTData, Infinidat, HITACHI VSP)\n      - add QSAN\n      - add EqualLogic PS\n      - Add Quantum devices\n      - Enable ALUA for AStor/NeoSapphire\n      - Update NFINIDAT/InfiniBox config\n      - Fix product blacklist of S/390 devices\n      - Add Seagate Lyve\n      - Add HITACHI VSP One SDS Block\n      - Add SCST (SCSI Target Subsystem for Linux)\n      - Huawei storage arrays\n      - XSG1 vendors\n    * Avoid a possible system hang during shutdown with queueing multipath maps.\n    * Failed paths should be checked every `polling_interval`. In certain cases,\n      this wouldn't happen, because the check interval wasn't reset by multipathd.\n    * It could happen that multipathd would accidentally release a SCSI persistent\n      reservation held by another node. Fix it.\n    * After manually failing some paths and then reinstating them, sometimes\n      the reinstated paths were immediately failed again by multipathd.\n    * Fixed the problem that, if there were multiple maps with deferred failback\n      (`failback` value \u003e 0 in `multipath.conf`), some maps might fail back later\n      than configured.\n    * Fixed a problem in the marginal path detection algorithm that could cause\n      the io error check for a recently failed path to be delayed.\n    * Fixed a minor bug in the config file parser\n    * Fixed minor issues detected by coverity.\n- Version 0.9.8+111+suse.b7ee850:\n  - Backported bug fixes from upstream 0.9.9 - 0.10.2\n    * Fixed old mpathpersist bug leading to the error message \"configured reservation\n      key doesn't match: 0x0\" when `reservation_key` was configured in the\n      multipaths section of `multipath.conf`. (bsc#1228926, gh#opensvc/multipath-tools#92)\n    * Fixed bug that caused queueing to be always disabled if flushing a map failed\n      (bug introduced in 0.9.8). (bsc#1229898)\n    * Fixed output of `multipath -t` and `multipath -T` for the options\n      `force_sync` and `retrigger_tries`. (bsc#1229898, gh#opensvc/multipath-tools#88)\n    * libmultipath: don't print error message if WATCHDOG_USEC is 0 (bsc#1232227)\n    * Fix map failure count for no_path_retry \u003e 0 (bsc#1229898)\n    * Fix reboot hang if uevent is processed for suspended device (bsc#1232063)\n    * libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL (bsc#1229898)\n    * Fixed a memory leak in the nvme foreign library. (bsc#1229898, bsc#1236390)\n    * Fix multipathd crash because of invalid path group index value, for example if an invalid\n      path device was removed from a map. (gh#opensvc/multipath-tools#105, bsc#1236392)\n    * Fix the problem that `group_by_tpg` might be disabled if one or more\n      paths were offline during initial configuration (bsc#1236392)\n    * Make sure udev and systemd notice changes in multipath path state\n      when devices are added to or removed from multipath maps (bsc#1236321)\n- Version 0.9.8+88+suse.d504d83:\n  * Revert \"libmultipath: fix max_sectors_kb on adding path\" (bsc#1222458)\n- Update to version 0.9.8+87+suse.f72b9f3:\n  * fix misspelled DM_UDEV_DISABLE_OTHER_RULES_FLAG in udev rules (bsc#1220810)\n- Remove libmpathpersist-example-old.c, which has been obsolete since multipath-tools 0.8.6.\n- Version 0.9.8+83+suse.bcae610 (bsc#1220374):\n  * multipath-tools: added NEWS.md\n- Version 0.9.8~1+82+suse.dcd98a3:\n  * Adapt package version such that it shows as a 0.9.8 prerelease\n  * Add missing udev rules file\n- Version 0.9.7+148+suse.9780ae0:\n  * 11-dm-mpath.rules: Fix quoting mistake (bsc#1219142)\n- Version 0.9.7+148+suse.7d9953e.obscpio\n  * This is a multipath-tools 0.9.8 pre-release\n  * fix fast_io_fail for Infinibox (bsc#1219348)\n  * Fix activation of LVM volume groups during coldplug (bsc#1219142)\n- Version 0.9.7+140+suse.2d78457:\n  * Socket activation via multipathd.socket has been disabled by default\n    because it has undesirable side effects on systems without multipath.\n    Users with multipath hardware should enable multipathd.service\n  * The restorequeueing CLI command now only enables queueing if\n    disablequeueing had been sent before\n  * Avoid multipathd hang during map flush\n  * multipathd now tracks the queueing mode of maps in its internal features string\n  * Improve error messages in 'multipathd -k'\n  * Fix segfault in autoresize code (bsc#1219289)\n  * Fix missing map reloads (bsc#1219796)\n  * Documentation fixes, spelling fixes, minor code fixes\n- Version 0.9.7+93+suse.e2f2272:\n  * fix ANA prioritizer enablement logic (bsc#1218326)\n  * avoid setting queue_if_no_path on multipath maps for which the\n    no_path_retry timeout has expired\n  * the interactive commands \"restorequeueing map X\" and\n    \"restorequeing maps\" now only affect maps that had queueing\n    manually disabled using \"disablequeuing maps\" or\n    \"disablequeuing map X\" beforehand\n  * Spelling fixes\n- Version 0.9.7+76+suse.5f857af:\n  * Update to upstream 0.9.7 (jsc#PED-6464)\n  * added max_retries config option to limit SCSI retries\n  * added auto_resize config option to enable resizing multipath maps automatically\n  * fixed memory and error handling for code using aio (marginal path code,\n    directio path checker)\n  * dropped modules-load.d/multipath.conf; replaced by a dependency on\n    modprobe@dm-multipath.service (systemd \u003e= 245: SLE15-SP3 and later only)\n    and a softdep on sd_mod for the SCSI device handlers (bsc#1217377)\n  * On SLE/Leap suse-module-tools doesn't ship a scsi_mod-\u003esd_mod softdep yet.\n    Add it here, too. It will be overridden by s-m-t when it's added there.\n  * drop usr_prefix= setting in SLE build recipes (set to /usr by upstream\n    automatically)\n- Version 0.9.6+115+suse.07776fb\n  * multipathd: Added support to handle FPIN-Li events for FC-NVMe\n- Update to version 0.9.6+110+suse.5dfdf35:\n  * The options \"bindings_file\", \"prkeys_file\", and \"wwids_file\",\n    which have been deprecated since multipath-tools 0.8.8,\n    aren't supported any more. The paths to these files are now\n    hard-coded to \"bindings\", \"prkeys\" and \"wwids\" under\n    /etc/multipath.\n  * Strictly avoid assigning map aliases that are already taken\n    (bsc#1213265)\n  * Improve handling of user-friendly names\n  * avoid \"multipath -d\" (dry-run) changing SCSI timeouts in sysfs (bsc#1213809)\n- `spec` file:\n * adapt prefix values to upstream changes\n * fix compilation flags for `make check`\n * pass EXTRAVERSION to build (bsc#1212854)\n","modified":"2026-08-12T18:23:40.487449265Z","published":"2026-08-06T08:40:43Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623054-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212854"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213265"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213809"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217377"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218326"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219142"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219348"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1220374"},{"type":"REPORT","url":"https://bugzilla.suse.com/1220810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1222458"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228926"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229898"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232063"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236321"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236390"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236392"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253260"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254094"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255285"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257007"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257244"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268144"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268145"}],"affected":[{"package":{"name":"multipath-tools","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/multipath-tools&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.8+292+suse.c0523c1-1.1"}]}],"ecosystem_specific":{"binaries":[{"kpartx":"0.9.8+292+suse.c0523c1-1.1","libmpath0":"0.9.8+292+suse.c0523c1-1.1","multipath-tools":"0.9.8+292+suse.c0523c1-1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23054-1.json"}}],"schema_version":"1.9.0"}