Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

openSUSE qemu Moderate Heap Overflow Info Leak Vuln 2026-2388-1

opensuse
Calendar Grey June 12, 2026
Scroller Opensuse
# Security update for qemu Announcement ID: SUSE-SU-2026:2388-1 Release Date: 2026-06-12T13:59:31Z R
An update that solves two vulnerabilities and has one security fix can now be installed.

Description

This update for qemu fixes the following issues:

Security fixes:

* CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a

12-byte information leak when processing specially crafted VMDK files

(bsc#1258509).

* CVE-2026-3842: hyperv/syndbg: missing mapped-length guard after

cpu_physical_memory_map causes host OOB write (bsc#1262089).

Other fixes:

* [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023)

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch SUSE-2026-2388=1

* SUSE Linux Enterprise Micro 5.5

zypper in -t patch SUSE-SLE-Micro-5.5-2026-2388=1

* Server Applications Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2388=1

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586)

* qemu-ivshmem-tools-7.1.0-150500.49.42.1

* qemu-audio-dbus-debuginfo-7.1.0-150500.49.42.1

* qemu-ppc-debuginfo-7.1.0-150500.49.42.1

* qemu-chardev-spice-debuginfo-7.1.0-150500.49.42.1

* qemu-hw-s390x-virtio-gpu-ccw-7.1.0-150500.49.42.1

* qemu-hw-display-virtio-gpu-pci-7.1.0-150500.49.42.1

* qemu-ui-spice-core-7.1.0-150500.49.42.1

* qemu-ui-opengl-debuginfo-7.1.0-150500.49.42.1

* qemu-block-ssh-7.1.0-150500.49.42.1

* qemu-guest-agent-debuginfo-7.1.0-150500.49.42.1

* qemu-audio-alsa-7.1.0-150500.49.42.1

* qemu-accel-tcg-x86-debuginfo-7.1.0-150500.49.42.1

* qemu-ui-spice-core-debuginfo-7.1.0-150500.49.42.1

* qemu-hw-usb-smartcard-debuginfo-7.1.0-150500.49.42.1

* qemu-block-iscsi-7.1.0-150500.49.42.1

* qemu-audio-jack-7.1.0-150500.49.42.1

* qemu-audio-alsa-debuginfo-7.1.0-150500.49.42.1

* qemu-s390x-debuginfo-7.1.0-150500.49.42.1

* qemu-x86-7.1.0-150500.49.42.1

* qemu-extra-debuginfo-7.1.0-150500.49.42.1

* qemu-block-curl-debuginfo-7.1.0-150500.49.42.1

*...

Read the Full Advisory

References

* bsc#1199023

* bsc#1258509

* bsc#1262089

## References:

* https://www.suse.com/security/cve/CVE-2026-2243.html

* https://www.suse.com/security/cve/CVE-2026-3842.html

* https://bugzilla.suse.com/show_bug.cgi?id=1199023

* https://bugzilla.suse.com/show_bug.cgi?id=1258509

* https://bugzilla.suse.com/show_bug.cgi?id=1262089

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2388-1
Release Date: 2026-06-12T13:59:31Z
Affected Products: * openSUSE Leap 15.5 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.