This update for qemu fixes the following issues:
Security issues fixed:
* CVE-2023-1544: out-of-bounds read in VMWare's paravirtual RDMA device
operations can be exploited through a malicious guest driver to crash the
QEMU process on the host (bsc#1209554).
* CVE-2024-6505: heap-based buffer overflow in the virtio-net device
operations can be exploited by a malicious privileged user to crash the QEMU
process on the host (bsc#1227397).
* CVE-2025-12464: stack-based buffer overflow in the e1000 network device
operations can be exploited by a malicious guest user to crash the QEMU
process on the host (bsc#1253002).
Other updates and bugfixes:
* [openSUSE][RPM] spec: require qemu-hw-display-virtio-gpu-pci for x86 too.
* [openSUSE][RPM} spec: delete old specfile constructs.
* block/curl: fix curl internal handles handling (bsc#1252768).
* [openSUSE][RPM]: really fix *-virtio-gpu-pci dependency on ARM
(bsc#1254286).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-43=1
* SUSE Manager Proxy 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2026-43=1
* SUSE Manager Retail Branch Server 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-
Server-4.3-LTS-2026-43=1
* SUSE Manager Server 4.3 LTS
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2026-43=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-43=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-43=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-43=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-43=1
* SUSE Linux Enterprise Micro...
Read the Full Advisory* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* qemu-block-curl-6.2.0-150400.37.46.1
* qemu-hw-usb-host-debuginfo-6.2.0-150400.37.46.1
* qemu-ui-opengl-debuginfo-6.2.0-150400.37.46.1
* qemu-hw-usb-host-6.2.0-150400.37.46.1
* qemu-hw-usb-redirect-6.2.0-150400.37.46.1
* qemu-hw-display-virtio-vga-debuginfo-6.2.0-150400.37.46.1
* qemu-block-iscsi-debuginfo-6.2.0-150400.37.46.1
* qemu-guest-agent-debuginfo-6.2.0-150400.37.46.1
* qemu-6.2.0-150400.37.46.1
* qemu-ui-curses-6.2.0-150400.37.46.1
* qemu-lang-6.2.0-150400.37.46.1
* qemu-debuginfo-6.2.0-150400.37.46.1
* qemu-hw-display-qxl-6.2.0-150400.37.46.1
* qemu-debugsource-6.2.0-150400.37.46.1
* qemu-block-rbd-6.2.0-150400.37.46.1
* qemu-hw-display-virtio-vga-6.2.0-150400.37.46.1
* qemu-tools-6.2.0-150400.37.46.1
* qemu-block-ssh-debuginfo-6.2.0-150400.37.46.1
* qemu-ui-gtk-6.2.0-150400.37.46.1
* qemu-chardev-baum-6.2.0-150400.37.46.1
* qemu-block-iscsi-6.2.0-150400.37.46.1
* qemu-chardev-spice-6.2.0-150400.37.46.1
*...
Read the Full Advisory* bsc#1209554
* bsc#1227397
* bsc#1252768
* bsc#1253002
* bsc#1254286
## References:
* https://www.suse.com/security/cve/CVE-2023-1544.html
* https://www.suse.com/security/cve/CVE-2024-6505.html
* https://www.suse.com/security/cve/CVE-2025-12464.html
* https://bugzilla.suse.com/show_bug.cgi?id=1209554
* https://bugzilla.suse.com/show_bug.cgi?id=1227397
* https://bugzilla.suse.com/show_bug.cgi?id=1252768
* https://bugzilla.suse.com/show_bug.cgi?id=1253002
* https://bugzilla.suse.com/show_bug.cgi?id=1254286
Get the latest Linux and open source security news straight to your inbox.