This update for qemu fixes the following issues:
* CVE-2025-11234: Fixed use-after-free in websocket handshake code can lead to
denial of service (bsc#1250984).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2026-356=1
* SUSE Linux Enterprise Micro 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-356=1
* SUSE Linux Enterprise Micro for Rancher 5.2
zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-356=1
* openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586)
* qemu-extra-debuginfo-5.2.0-150300.142.1
* qemu-block-gluster-5.2.0-150300.142.1
* qemu-s390x-debuginfo-5.2.0-150300.142.1
* qemu-vhost-user-gpu-debuginfo-5.2.0-150300.142.1
* qemu-hw-usb-redirect-5.2.0-150300.142.1
* qemu-ivshmem-tools-debuginfo-5.2.0-150300.142.1
* qemu-ppc-5.2.0-150300.142.1
* qemu-block-curl-debuginfo-5.2.0-150300.142.1
* qemu-block-ssh-debuginfo-5.2.0-150300.142.1
* qemu-block-iscsi-5.2.0-150300.142.1
* qemu-block-dmg-debuginfo-5.2.0-150300.142.1
* qemu-linux-user-debugsource-5.2.0-150300.142.1
* qemu-5.2.0-150300.142.1
* qemu-chardev-spice-debuginfo-5.2.0-150300.142.1
* qemu-hw-s390x-virtio-gpu-ccw-5.2.0-150300.142.1
* qemu-hw-usb-smartcard-debuginfo-5.2.0-150300.142.1
* qemu-ivshmem-tools-5.2.0-150300.142.1
* qemu-audio-pa-debuginfo-5.2.0-150300.142.1
* qemu-ui-gtk-5.2.0-150300.142.1
* qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.142.1
* qemu-audio-spice-debuginfo-5.2.0-150300.142.1
*...
Read the Full Advisory* bsc#1250984
## References:
* https://www.suse.com/security/cve/CVE-2025-11234.html
* https://bugzilla.suse.com/show_bug.cgi?id=1250984
Get the latest Linux and open source security news straight to your inbox.