This update for qemu fixes the following issues:
* CVE-2021-3611: Fixed segmentation fault due to stack overflow (bsc#1193914).
Other fixes:
* qemu.spec: mark bridge.conf as noreplace (bsc#1201944).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-432=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2025-432=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-432=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-432=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2025-432=1
* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
* qemu-ui-opengl-6.2.0-150400.37.40.1
* qemu-guest-agent-6.2.0-150400.37.40.1
* qemu-hw-usb-redirect-6.2.0-150400.37.40.1
* qemu-chardev-spice-6.2.0-150400.37.40.1
* qemu-hw-display-virtio-gpu-debuginfo-6.2.0-150400.37.40.1
* qemu-audio-spice-6.2.0-150400.37.40.1
* qemu-debugsource-6.2.0-150400.37.40.1
* qemu-ui-opengl-debuginfo-6.2.0-150400.37.40.1
* qemu-hw-display-virtio-gpu-6.2.0-150400.37.40.1
* qemu-chardev-spice-debuginfo-6.2.0-150400.37.40.1
* qemu-ui-spice-core-6.2.0-150400.37.40.1
* qemu-audio-spice-debuginfo-6.2.0-150400.37.40.1
* qemu-hw-display-virtio-vga-debuginfo-6.2.0-150400.37.40.1
* qemu-tools-6.2.0-150400.37.40.1
* qemu-tools-debuginfo-6.2.0-150400.37.40.1
* qemu-ui-spice-core-debuginfo-6.2.0-150400.37.40.1
* qemu-guest-agent-debuginfo-6.2.0-150400.37.40.1
* qemu-debuginfo-6.2.0-150400.37.40.1
* qemu-hw-usb-redirect-debuginfo-6.2.0-150400.37.40.1
* qemu-hw-display-virtio-vga-6.2.0-150400.37.40.1
*...
Read the Full Advisory* bsc#1193914
* bsc#1201944
## References:
* https://www.suse.com/security/cve/CVE-2021-3611.html
* https://bugzilla.suse.com/show_bug.cgi?id=1193914
* https://bugzilla.suse.com/show_bug.cgi?id=1201944
Get the latest Linux and open source security news straight to your inbox.