Explore top 10 tips to secure your open-source projects now. Read More
×* bsc#1084909 * bsc#1220065 * bsc#1220310 * bsc#1222218 * bsc#1222841 . # Security update for qemu Announcement ID: SUSE-SU-2025:20011-1 Release Date: 2025-02-03T08:47:43Z Rating: critical References: * bsc#1084909 * bsc#1220065 * bsc#1220310 * bsc#1222218 * bsc#1222841 * bsc#1222843 * bsc#1222845 * bsc#1224179 Cross-References: * CVE-2024-26328 * CVE-2024-3446 * CVE-2024-3447 * CVE-2024-3567 CVSS scores: * CVE-2024-26328 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-26328 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-26328 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3446 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2024-3446 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2024-3447 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3447 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3567 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3567 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has four fixes can now be installed. ## Description: This update for qemu fixes the following issues: * Update to version 8.2.5: * target/loongarch: fix a wrong print in cpu dump * ui/sdl2: Allow host to power down screen * target/i386: fix SSE and SSE2 feature check * target/i386: fix xsave.flat from kvm-unit-tests * disas/riscv: Decode all of the pmpcfg and pmpaddr CSRs * target/riscv/kvm.c: Fix the hart bit setting of AIA * target/riscv: rvzicbo: Fixup CBO extension register calculation * target/riscv: do not set mtval2 for non guest-page faults * target/riscv: prioritize pmp errors in raise_mmu_exception() * target/riscv: rvv: Remove redudant SEW checking for vector fpnarrow/widen instructions * target/riscv: rvv: Check single width operator for vfncvt.rod.f.f.w * target/riscv: rvv: Check single width operator for vector fp widen instructions * target/riscv: rvv: Fix Zvfhmin checking for vfwcvt.f.f.v and vfncvt.f.f.w instructions * target/riscv/cpu.c: fix Zvkb extension config * target/riscv: Fix the element agnostic function problem * target/riscv/kvm: tolerate KVM disable ext errors * hw/intc/riscv_aplic: APLICs should add child earlier than realize * iotests: test NBD+TLS+iothread * qio: Inherit follow_coroutine_ctx across TLS * target/arm: Disable SVE extensions when SVE is disabled * hw/intc/arm_gic: Fix handling of NS view of GICC_APR * hvf: arm: Fix encodings for ID_AA64PFR1_EL1 and debug System registers * gitlab: use 'setarch -R' to workaround tsan bug * gitlab: use $MAKE instead of 'make' * dockerfiles: add 'MAKE' env variable to remaining containers * gitlab: Update msys2-64bit runner tags * target/i386: no single-step exception after MOV or POP SS * Update to version 8.2.4. * target/sh4: Fix SUBV opcode * target/sh4: Fix ADDV opcode * hw/arm/npcm7xx: Store derivative OTP fuse key in little endian * hw/dmax/xlnx_dpdma: fix handling of address_extension descriptor fields * hw/ufs: Fix buffer overflow bug * tests/avocado: update sunxi kernel from armbian to 6.6.16 * target/loongarch/cpu.c: typo fix: expection * backends/cryptodev-builtin: Fix local_error leaks * nbd/server: Mark negotiation functions as coroutine_fn * nbd/server: do not poll within a coroutine context * linux-user: do_setsockopt: fix SOL_ALG.ALG_SET_KEY * target/riscv/kvm: change timer regs size to u64 * target/riscv/kvm: change KVM_REG_RISCV_FP_D to u64 * target/riscv/kvm: change KVM_REG_RISCV_FP_F to u32 * Update to version 8.2.3. * Update version for 8.2.3 release * ppc/spapr: Initialize max_cpus limit to SPAPR_IRQ_NR_IPIS. * ppc/spapr: Introduce SPAPR_IRQ_NR_IPIS to refer IRQ range for CPU IPIs. *hw/pci-host/ppc440_pcix: Do not expose a bridge device on PCI bus * hw/isa/vt82c686: Keep track of PIRQ/PINT pins separately * virtio-pci: fix use of a released vector * linux-user/x86_64: Handle the vsyscall page in open_self_maps_{2,4} * hw/audio/virtio-snd: Remove unused assignment * hw/net/net_tx_pkt: Fix overrun in update_sctp_checksum() * hw/sd/sdhci: Do not update TRNMOD when Command Inhibit (DAT) is set * hw/net/lan9118: Fix overflow in MIL TX FIFO * hw/net/lan9118: Replace magic '2048' value by MIL_TXFIFO_SIZE definition * backends/cryptodev: Do not abort for invalid session ID * hw/misc/applesmc: Fix memory leak in reset() handler * hw/block/nand: Fix out-of-bound access in NAND block buffer * hw/block/nand: Have blk_load() take unsigned offset and return boolean * hw/block/nand: Factor nand_load_iolen() method out * qemu-options: Fix CXL Fixed Memory Window interleave-granularity typo * hw/virtio/virtio-crypto: Protect from DMA re-entrancy bugs * hw/char/virtio-serial-bus: Protect from DMA re-entrancy bugs * hw/display/virtio-gpu: Protect from DMA re-entrancy bugs * mirror: Don't call job_pause_point() under graph lock (bsc#1224179) * Backports and bugfixes: * hw/net/net_tx_pkt: Fix overrun in update_sctp_checksum() (bsc#1222841, CVE-2024-3567) * hw/virtio/virtio-crypto: Protect from DMA re-entrancy bugs (bsc#1222843, CVE-2024-3446) * hw/char/virtio-serial-bus: Protect from DMA re-entrancy bugs (bsc#1222843, CVE-2024-3446) * hw/display/virtio-gpu: Protect from DMA re-entrancy bugs (bsc#1222843, CVE-2024-3446) * hw/virtio: Introduce virtio_bh_new_guarded() helper (bsc#1222843, CVE-2024-3446) * hw/sd/sdhci: Do not update TRNMOD when Command Inhibit (DAT) is set (bsc#1222845, CVE-2024-3447) * hw/nvme: Use pcie_sriov_num_vfs() (bsc#1220065, CVE-2024-26328) * Update to version 8.2.2 * chardev/char-socket: Fix TLS io channels sending too much data to the backend * tests/unit/test-util-sockets: Remove temporary fileafter test * hw/usb/bus.c: PCAP adding 0xA in Windows version * hw/intc/Kconfig: Fix GIC settings when using "\--without-default-devices" * gitlab: force allow use of pip in Cirrus jobs * tests/vm: avoid re-building the VM images all the time * tests/vm: update openbsd image to 7.4 * target/i386: leave the A20 bit set in the final NPT walk * target/i386: remove unnecessary/wrong application of the A20 mask * target/i386: Fix physical address truncation * target/i386: check validity of VMCB addresses * target/i386: mask high bits of CR3 in 32-bit mode * pl031: Update last RTCLR value on write in case it's read back * hw/nvme: fix invalid endian conversion * update edk2 binaries to edk2-stable202402 * update edk2 submodule to edk2-stable202402 * target/ppc: Fix crash on machine check caused by ifetch * target/ppc: Fix lxv/stxv MSR facility check * .gitlab-ci.d/windows.yml: Drop msys2-32bit job * system/vl: Update description for input grab key * docs/system: Update description for input grab key * hw/hppa/Kconfig: Fix building with "configure --without-default-devices" * tests/qtest: Depend on dbus_display1_dep * meson: Explicitly specify dbus-display1.h dependency * audio: Depend on dbus_display1_dep * ui/console: Fix console resize with placeholder surface * ui/clipboard: add asserts for update and request * ui/clipboard: mark type as not available when there is no data * ui: reject extended clipboard message if not activated * target/i386: Generate an illegal opcode exception on cmp instructions with lock prefix * i386/cpuid: Move leaf 7 to correct group * i386/cpuid: Decrease cpuid_i when skipping CPUID leaf 1F * i386/cpu: Mask with XCR0/XSS mask for FEAT_XSAVE_XCR0_HI and FEAT_XSAVE_XSS_HI leafs * i386/cpu: Clear FEAT_XSAVE_XSS_LO/HI leafs when CPUID_EXT_XSAVE is not available * .gitlab-ci/windows.yml: Don't install libusb or spice packages on 32-bit * iotests: Make 144 deterministic again * target/arm: Don't get MDCR_EL2 inpmu_counter_enabled() before checking ARM_FEATURE_PMU * target/arm: Fix SVE/SME gross MTE suppression checks * target/arm: Handle mte in do_ldrq, do_ldro * Address bsc#1220310. Backported upstream commits: * ppc/spapr: Initialize max_cpus limit to SPAPR_IRQ_NR_IPIS * ppc/spapr: Introduce SPAPR_IRQ_NR_IPIS to refer IRQ range for CPU IPIs. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-10=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * qemu-hw-display-qxl-8.2.5-1.1 * qemu-block-ssh-debuginfo-8.2.5-1.1 * qemu-ui-opengl-8.2.5-1.1 * qemu-hw-display-virtio-gpu-pci-8.2.5-1.1 * qemu-ui-opengl-debuginfo-8.2.5-1.1 * qemu-guest-agent-8.2.5-1.1 * qemu-hw-usb-redirect-8.2.5-1.1 * qemu-audio-spice-8.2.5-1.1 * qemu-hw-display-virtio-vga-debuginfo-8.2.5-1.1 * qemu-chardev-spice-8.2.5-1.1 * qemu-block-curl-8.2.5-1.1 * qemu-tools-8.2.5-1.1 * qemu-tools-debuginfo-8.2.5-1.1 * qemu-hw-display-virtio-gpu-8.2.5-1.1 * qemu-debuginfo-8.2.5-1.1 * qemu-8.2.5-1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-8.2.5-1.1 * qemu-ui-spice-core-debuginfo-8.2.5-1.1 * qemu-block-iscsi-8.2.5-1.1 * qemu-chardev-spice-debuginfo-8.2.5-1.1 * qemu-debugsource-8.2.5-1.1 * qemu-ui-spice-core-8.2.5-1.1 * qemu-block-rbd-debuginfo-8.2.5-1.1 * qemu-block-ssh-8.2.5-1.1 * qemu-hw-display-qxl-debuginfo-8.2.5-1.1 * qemu-block-rbd-8.2.5-1.1 * qemu-hw-display-virtio-gpu-debuginfo-8.2.5-1.1 * qemu-hw-usb-host-debuginfo-8.2.5-1.1 * qemu-ksm-8.2.5-1.1 * qemu-block-curl-debuginfo-8.2.5-1.1 * qemu-pr-helper-8.2.5-1.1 * qemu-hw-usb-host-8.2.5-1.1 * qemu-img-8.2.5-1.1 * qemu-img-debuginfo-8.2.5-1.1 * qemu-audio-spice-debuginfo-8.2.5-1.1 *qemu-hw-display-virtio-vga-8.2.5-1.1 * qemu-block-iscsi-debuginfo-8.2.5-1.1 * qemu-pr-helper-debuginfo-8.2.5-1.1 * qemu-hw-usb-redirect-debuginfo-8.2.5-1.1 * qemu-guest-agent-debuginfo-8.2.5-1.1 * qemu-lang-8.2.5-1.1 * SUSE Linux Micro 6.0 (x86_64) * qemu-accel-tcg-x86-8.2.5-1.1 * qemu-x86-8.2.5-1.1 * qemu-accel-tcg-x86-debuginfo-8.2.5-1.1 * qemu-x86-debuginfo-8.2.5-1.1 * SUSE Linux Micro 6.0 (noarch) * qemu-vgabios-8.2.51.16.3_3_ga95067eb-1.1 * qemu-ipxe-8.2.5-1.1 * qemu-seabios-8.2.51.16.3_3_ga95067eb-1.1 * SUSE Linux Micro 6.0 (s390x) * qemu-s390x-debuginfo-8.2.5-1.1 * qemu-s390x-8.2.5-1.1 * SUSE Linux Micro 6.0 (aarch64) * qemu-arm-8.2.5-1.1 * qemu-arm-debuginfo-8.2.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-26328.html * https://www.suse.com/security/cve/CVE-2024-3446.html * https://www.suse.com/security/cve/CVE-2024-3447.html * https://www.suse.com/security/cve/CVE-2024-3567.html * https://bugzilla.suse.com/show_bug.cgi?id=1084909 * https://bugzilla.suse.com/show_bug.cgi?id=1220065 * https://bugzilla.suse.com/show_bug.cgi?id=1220310 * https://bugzilla.suse.com/show_bug.cgi?id=1222218 * https://bugzilla.suse.com/show_bug.cgi?id=1222841 * https://bugzilla.suse.com/show_bug.cgi?id=1222843 * https://bugzilla.suse.com/show_bug.cgi?id=1222845 * https://bugzilla.suse.com/show_bug.cgi?id=1224179 . Important security patch released for qemu on SUSE Linux Micro. This update resolves numerous vulnerabilities. Apply immediately to ensure system protection.. SUSE Linux Micro,QEMU security update,critical patch,system vulnerabilities,software vulnerability fix. . Severity: Critical. LinuxSecurity.com Team
* bsc#1221812 * bsc#1227322 * bsc#1229007 Cross-References: . # Security update for qemu Announcement ID: SUSE-SU-2025:20036-1 Release Date: 2025-02-03T08:53:01Z Rating: important References: * bsc#1221812 * bsc#1227322 * bsc#1229007 Cross-References: * CVE-2024-4467 * CVE-2024-7409 CVSS scores: * CVE-2024-4467 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-4467 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-7409 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for qemu fixes the following issues: * Fix bsc#1221812: * block: Reschedule query-block during qcow2 invalidation (bsc#1221812) * Fix bsc#1229007, CVE-2024-7409: * nbd/server: CVE-2024-7409: Close stray clients at server-stop (bsc#1229007) * nbd/server: CVE-2024-7409: Drop non-negotiating clients (bsc#1229007) * nbd/server: CVE-2024-7409: Cap default max-connections to 100 (bsc#1229007) * nbd/server: Plumb in new args to nbd_client_add() (bsc#1229007, CVE-2024-7409) * nbd: Minor style and typo fixes (bsc#1229007, CVE-2024-7409) * Update to version 8.2.6: Full backport lists (from the various releases) here: https://lore.kernel.org/qemu- devel/1721203806.547734.831464.nullmailer@tls.msk.ru/ Some of the upstream backports are: hw/nvme: fix number of PIDs for FDP RUH update sphinx/qapidoc: Fix to generate doc for explicit, unboxed arguments char- stdio: Restore blocking mode of stdout on exit virtio: remove virtio_tswap16s() call in vring_packed_event_read() virtio-pci: Fix the failure process in kvm_virtio_pci_vector_use_one() block: Parse filenames only when explicitly requested iotests/270: Don'tstore data-file with json: prefix in image iotests/244: Don't store data-file with protocol in image qcow2: Don't open data_file with BDRV_O_NO_IO (bsc#1227322, CVE-2024-4467) target/arm: Fix FJCVTZS vs flush-to-zero target/arm: Fix VCMLA Dd, Dn, Dm[idx] i386/cpu: fixup number of addressable IDs for processor cores in the physical package tests: Update our CI to use CentOS Stream 9 instead of 8 migration: Fix file migration with fdset tcg/loongarch64: Fix tcg_out_movi vs some pcrel pointers target/sparc: use signed denominator in sdiv helper linux-user: Make TARGET_NR_setgroups affect only the current thread accel/tcg: Fix typo causing tb-> page_addr[1] to not be recorded stdvga: fix screen blanking hw/audio/virtio-snd: Always use little endian audio format ui/gtk: Draw guest frame at refresh cycle virtio-net: drop too short packets early target/i386: fix size of EBP writeback in gen_enter() ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-60=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * qemu-ui-opengl-8.2.6-1.1 * qemu-block-iscsi-debuginfo-8.2.6-1.1 * qemu-pr-helper-8.2.6-1.1 * qemu-audio-spice-8.2.6-1.1 * qemu-8.2.6-1.1 * qemu-block-ssh-debuginfo-8.2.6-1.1 * qemu-tools-debuginfo-8.2.6-1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-8.2.6-1.1 * qemu-ui-opengl-debuginfo-8.2.6-1.1 * qemu-hw-display-virtio-vga-8.2.6-1.1 * qemu-pr-helper-debuginfo-8.2.6-1.1 * qemu-block-curl-debuginfo-8.2.6-1.1 * qemu-block-rbd-8.2.6-1.1 * qemu-block-rbd-debuginfo-8.2.6-1.1 * qemu-img-debuginfo-8.2.6-1.1 * qemu-ksm-8.2.6-1.1 * qemu-ui-spice-core-debuginfo-8.2.6-1.1 * qemu-block-iscsi-8.2.6-1.1 * qemu-tools-8.2.6-1.1 * qemu-img-8.2.6-1.1 * qemu-block-curl-8.2.6-1.1 *qemu-hw-usb-host-debuginfo-8.2.6-1.1 * qemu-hw-display-qxl-debuginfo-8.2.6-1.1 * qemu-lang-8.2.6-1.1 * qemu-hw-display-virtio-vga-debuginfo-8.2.6-1.1 * qemu-ui-spice-core-8.2.6-1.1 * qemu-block-ssh-8.2.6-1.1 * qemu-hw-usb-redirect-debuginfo-8.2.6-1.1 * qemu-guest-agent-8.2.6-1.1 * qemu-hw-display-qxl-8.2.6-1.1 * qemu-hw-display-virtio-gpu-pci-8.2.6-1.1 * qemu-hw-display-virtio-gpu-8.2.6-1.1 * qemu-debugsource-8.2.6-1.1 * qemu-guest-agent-debuginfo-8.2.6-1.1 * qemu-chardev-spice-8.2.6-1.1 * qemu-hw-usb-host-8.2.6-1.1 * qemu-chardev-spice-debuginfo-8.2.6-1.1 * qemu-audio-spice-debuginfo-8.2.6-1.1 * qemu-hw-usb-redirect-8.2.6-1.1 * qemu-hw-display-virtio-gpu-debuginfo-8.2.6-1.1 * qemu-debuginfo-8.2.6-1.1 * SUSE Linux Micro 6.0 (x86_64) * qemu-accel-tcg-x86-8.2.6-1.1 * qemu-x86-debuginfo-8.2.6-1.1 * qemu-accel-tcg-x86-debuginfo-8.2.6-1.1 * qemu-x86-8.2.6-1.1 * SUSE Linux Micro 6.0 (noarch) * qemu-vgabios-8.2.61.16.3_3_ga95067eb-1.1 * qemu-seabios-8.2.61.16.3_3_ga95067eb-1.1 * qemu-ipxe-8.2.6-1.1 * SUSE Linux Micro 6.0 (s390x) * qemu-s390x-8.2.6-1.1 * qemu-s390x-debuginfo-8.2.6-1.1 * SUSE Linux Micro 6.0 (aarch64) * qemu-arm-debuginfo-8.2.6-1.1 * qemu-arm-8.2.6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4467.html * https://www.suse.com/security/cve/CVE-2024-7409.html * https://bugzilla.suse.com/show_bug.cgi?id=1221812 * https://bugzilla.suse.com/show_bug.cgi?id=1227322 * https://bugzilla.suse.com/show_bug.cgi?id=1229007 . This crucial patch for SUSE Linux Micro 6.0 addresses pivotal vulnerabilities in qemu, maintaining system security.. SUSE Linux Micro 6.0 update, qemu security fixes, software update SUSE. . Severity: Important. LinuxSecurity.com Team
* bsc#1084909 * bsc#1220065 * bsc#1220310 * bsc#1222218 * bsc#1222841 . # Security update for qemu Announcement ID: SUSE-SU-2025:20011-1 Release Date: 2025-02-03T08:47:43Z Rating: critical References: * bsc#1084909 * bsc#1220065 * bsc#1220310 * bsc#1222218 * bsc#1222841 * bsc#1222843 * bsc#1222845 * bsc#1224179 Cross-References: * CVE-2024-26328 * CVE-2024-3446 * CVE-2024-3447 * CVE-2024-3567 CVSS scores: * CVE-2024-26328 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-26328 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-26328 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3446 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2024-3446 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2024-3447 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3447 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3567 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3567 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has four fixes can now be installed. ## Description: This update for qemu fixes the following issues: * Update to version 8.2.5: * target/loongarch: fix a wrong print in cpu dump * ui/sdl2: Allow host to power down screen * target/i386: fix SSE and SSE2 feature check * target/i386: fix xsave.flat from kvm-unit-tests * disas/riscv: Decode all of the pmpcfg and pmpaddr CSRs * target/riscv/kvm.c: Fix the hart bit setting of AIA * target/riscv: rvzicbo: Fixup CBO extension register calculation * target/riscv: do not set mtval2 for non guest-page faults * target/riscv: prioritize pmp errors in raise_mmu_exception() * target/riscv: rvv: Remove redudant SEW checking for vector fpnarrow/widen instructions * target/riscv: rvv: Check single width operator for vfncvt.rod.f.f.w * target/riscv: rvv: Check single width operator for vector fp widen instructions * target/riscv: rvv: Fix Zvfhmin checking for vfwcvt.f.f.v and vfncvt.f.f.w instructions * target/riscv/cpu.c: fix Zvkb extension config * target/riscv: Fix the element agnostic function problem * target/riscv/kvm: tolerate KVM disable ext errors * hw/intc/riscv_aplic: APLICs should add child earlier than realize * iotests: test NBD+TLS+iothread * qio: Inherit follow_coroutine_ctx across TLS * target/arm: Disable SVE extensions when SVE is disabled * hw/intc/arm_gic: Fix handling of NS view of GICC_APR * hvf: arm: Fix encodings for ID_AA64PFR1_EL1 and debug System registers * gitlab: use 'setarch -R' to workaround tsan bug * gitlab: use $MAKE instead of 'make' * dockerfiles: add 'MAKE' env variable to remaining containers * gitlab: Update msys2-64bit runner tags * target/i386: no single-step exception after MOV or POP SS * Update to version 8.2.4. * target/sh4: Fix SUBV opcode * target/sh4: Fix ADDV opcode * hw/arm/npcm7xx: Store derivative OTP fuse key in little endian * hw/dmax/xlnx_dpdma: fix handling of address_extension descriptor fields * hw/ufs: Fix buffer overflow bug * tests/avocado: update sunxi kernel from armbian to 6.6.16 * target/loongarch/cpu.c: typo fix: expection * backends/cryptodev-builtin: Fix local_error leaks * nbd/server: Mark negotiation functions as coroutine_fn * nbd/server: do not poll within a coroutine context * linux-user: do_setsockopt: fix SOL_ALG.ALG_SET_KEY * target/riscv/kvm: change timer regs size to u64 * target/riscv/kvm: change KVM_REG_RISCV_FP_D to u64 * target/riscv/kvm: change KVM_REG_RISCV_FP_F to u32 * Update to version 8.2.3. * Update version for 8.2.3 release * ppc/spapr: Initialize max_cpus limit to SPAPR_IRQ_NR_IPIS. * ppc/spapr: Introduce SPAPR_IRQ_NR_IPIS to refer IRQ range for CPU IPIs. *hw/pci-host/ppc440_pcix: Do not expose a bridge device on PCI bus * hw/isa/vt82c686: Keep track of PIRQ/PINT pins separately * virtio-pci: fix use of a released vector * linux-user/x86_64: Handle the vsyscall page in open_self_maps_{2,4} * hw/audio/virtio-snd: Remove unused assignment * hw/net/net_tx_pkt: Fix overrun in update_sctp_checksum() * hw/sd/sdhci: Do not update TRNMOD when Command Inhibit (DAT) is set * hw/net/lan9118: Fix overflow in MIL TX FIFO * hw/net/lan9118: Replace magic '2048' value by MIL_TXFIFO_SIZE definition * backends/cryptodev: Do not abort for invalid session ID * hw/misc/applesmc: Fix memory leak in reset() handler * hw/block/nand: Fix out-of-bound access in NAND block buffer * hw/block/nand: Have blk_load() take unsigned offset and return boolean * hw/block/nand: Factor nand_load_iolen() method out * qemu-options: Fix CXL Fixed Memory Window interleave-granularity typo * hw/virtio/virtio-crypto: Protect from DMA re-entrancy bugs * hw/char/virtio-serial-bus: Protect from DMA re-entrancy bugs * hw/display/virtio-gpu: Protect from DMA re-entrancy bugs * mirror: Don't call job_pause_point() under graph lock (bsc#1224179) * Backports and bugfixes: * hw/net/net_tx_pkt: Fix overrun in update_sctp_checksum() (bsc#1222841, CVE-2024-3567) * hw/virtio/virtio-crypto: Protect from DMA re-entrancy bugs (bsc#1222843, CVE-2024-3446) * hw/char/virtio-serial-bus: Protect from DMA re-entrancy bugs (bsc#1222843, CVE-2024-3446) * hw/display/virtio-gpu: Protect from DMA re-entrancy bugs (bsc#1222843, CVE-2024-3446) * hw/virtio: Introduce virtio_bh_new_guarded() helper (bsc#1222843, CVE-2024-3446) * hw/sd/sdhci: Do not update TRNMOD when Command Inhibit (DAT) is set (bsc#1222845, CVE-2024-3447) * hw/nvme: Use pcie_sriov_num_vfs() (bsc#1220065, CVE-2024-26328) * Update to version 8.2.2 * chardev/char-socket: Fix TLS io channels sending too much data to the backend * tests/unit/test-util-sockets: Remove temporary fileafter test * hw/usb/bus.c: PCAP adding 0xA in Windows version * hw/intc/Kconfig: Fix GIC settings when using "\--without-default-devices" * gitlab: force allow use of pip in Cirrus jobs * tests/vm: avoid re-building the VM images all the time * tests/vm: update openbsd image to 7.4 * target/i386: leave the A20 bit set in the final NPT walk * target/i386: remove unnecessary/wrong application of the A20 mask * target/i386: Fix physical address truncation * target/i386: check validity of VMCB addresses * target/i386: mask high bits of CR3 in 32-bit mode * pl031: Update last RTCLR value on write in case it's read back * hw/nvme: fix invalid endian conversion * update edk2 binaries to edk2-stable202402 * update edk2 submodule to edk2-stable202402 * target/ppc: Fix crash on machine check caused by ifetch * target/ppc: Fix lxv/stxv MSR facility check * .gitlab-ci.d/windows.yml: Drop msys2-32bit job * system/vl: Update description for input grab key * docs/system: Update description for input grab key * hw/hppa/Kconfig: Fix building with "configure --without-default-devices" * tests/qtest: Depend on dbus_display1_dep * meson: Explicitly specify dbus-display1.h dependency * audio: Depend on dbus_display1_dep * ui/console: Fix console resize with placeholder surface * ui/clipboard: add asserts for update and request * ui/clipboard: mark type as not available when there is no data * ui: reject extended clipboard message if not activated * target/i386: Generate an illegal opcode exception on cmp instructions with lock prefix * i386/cpuid: Move leaf 7 to correct group * i386/cpuid: Decrease cpuid_i when skipping CPUID leaf 1F * i386/cpu: Mask with XCR0/XSS mask for FEAT_XSAVE_XCR0_HI and FEAT_XSAVE_XSS_HI leafs * i386/cpu: Clear FEAT_XSAVE_XSS_LO/HI leafs when CPUID_EXT_XSAVE is not available * .gitlab-ci/windows.yml: Don't install libusb or spice packages on 32-bit * iotests: Make 144 deterministic again * target/arm: Don't get MDCR_EL2 inpmu_counter_enabled() before checking ARM_FEATURE_PMU * target/arm: Fix SVE/SME gross MTE suppression checks * target/arm: Handle mte in do_ldrq, do_ldro * Address bsc#1220310. Backported upstream commits: * ppc/spapr: Initialize max_cpus limit to SPAPR_IRQ_NR_IPIS * ppc/spapr: Introduce SPAPR_IRQ_NR_IPIS to refer IRQ range for CPU IPIs. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-10=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * qemu-block-rbd-debuginfo-8.2.5-1.1 * qemu-guest-agent-8.2.5-1.1 * qemu-pr-helper-8.2.5-1.1 * qemu-ui-opengl-8.2.5-1.1 * qemu-block-ssh-debuginfo-8.2.5-1.1 * qemu-hw-display-virtio-gpu-debuginfo-8.2.5-1.1 * qemu-block-curl-8.2.5-1.1 * qemu-ksm-8.2.5-1.1 * qemu-block-curl-debuginfo-8.2.5-1.1 * qemu-chardev-spice-debuginfo-8.2.5-1.1 * qemu-hw-display-virtio-gpu-8.2.5-1.1 * qemu-pr-helper-debuginfo-8.2.5-1.1 * qemu-hw-display-virtio-gpu-pci-8.2.5-1.1 * qemu-tools-debuginfo-8.2.5-1.1 * qemu-hw-display-qxl-8.2.5-1.1 * qemu-ui-spice-core-debuginfo-8.2.5-1.1 * qemu-hw-display-virtio-vga-debuginfo-8.2.5-1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-8.2.5-1.1 * qemu-tools-8.2.5-1.1 * qemu-img-debuginfo-8.2.5-1.1 * qemu-debugsource-8.2.5-1.1 * qemu-ui-spice-core-8.2.5-1.1 * qemu-audio-spice-8.2.5-1.1 * qemu-hw-display-virtio-vga-8.2.5-1.1 * qemu-debuginfo-8.2.5-1.1 * qemu-ui-opengl-debuginfo-8.2.5-1.1 * qemu-hw-usb-redirect-8.2.5-1.1 * qemu-lang-8.2.5-1.1 * qemu-block-iscsi-8.2.5-1.1 * qemu-block-ssh-8.2.5-1.1 * qemu-guest-agent-debuginfo-8.2.5-1.1 * qemu-hw-usb-host-8.2.5-1.1 * qemu-img-8.2.5-1.1 * qemu-8.2.5-1.1 * qemu-block-iscsi-debuginfo-8.2.5-1.1 *qemu-hw-display-qxl-debuginfo-8.2.5-1.1 * qemu-audio-spice-debuginfo-8.2.5-1.1 * qemu-hw-usb-redirect-debuginfo-8.2.5-1.1 * qemu-chardev-spice-8.2.5-1.1 * qemu-block-rbd-8.2.5-1.1 * qemu-hw-usb-host-debuginfo-8.2.5-1.1 * SUSE Linux Micro 6.0 (x86_64) * qemu-x86-debuginfo-8.2.5-1.1 * qemu-accel-tcg-x86-debuginfo-8.2.5-1.1 * qemu-accel-tcg-x86-8.2.5-1.1 * qemu-x86-8.2.5-1.1 * SUSE Linux Micro 6.0 (noarch) * qemu-ipxe-8.2.5-1.1 * qemu-vgabios-8.2.51.16.3_3_ga95067eb-1.1 * qemu-seabios-8.2.51.16.3_3_ga95067eb-1.1 * SUSE Linux Micro 6.0 (s390x) * qemu-s390x-8.2.5-1.1 * qemu-s390x-debuginfo-8.2.5-1.1 * SUSE Linux Micro 6.0 (aarch64) * qemu-arm-8.2.5-1.1 * qemu-arm-debuginfo-8.2.5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-26328.html * https://www.suse.com/security/cve/CVE-2024-3446.html * https://www.suse.com/security/cve/CVE-2024-3447.html * https://www.suse.com/security/cve/CVE-2024-3567.html * https://bugzilla.suse.com/show_bug.cgi?id=1084909 * https://bugzilla.suse.com/show_bug.cgi?id=1220065 * https://bugzilla.suse.com/show_bug.cgi?id=1220310 * https://bugzilla.suse.com/show_bug.cgi?id=1222218 * https://bugzilla.suse.com/show_bug.cgi?id=1222841 * https://bugzilla.suse.com/show_bug.cgi?id=1222843 * https://bugzilla.suse.com/show_bug.cgi?id=1222845 * https://bugzilla.suse.com/show_bug.cgi?id=1224179 . Revise configurations to tackle numerous vulnerabilities in qemu with high priority that bolster operating efficiency and safeguard integrity.. qemu security, SUSE patch, critical update, Linux Micro security. . Severity: Critical. LinuxSecurity.com Team
* bsc#1221812 * bsc#1227322 * bsc#1229007 Cross-References: . # Security update for qemu Announcement ID: SUSE-SU-2025:20036-1 Release Date: 2025-02-03T08:53:01Z Rating: important References: * bsc#1221812 * bsc#1227322 * bsc#1229007 Cross-References: * CVE-2024-4467 * CVE-2024-7409 CVSS scores: * CVE-2024-4467 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-4467 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-7409 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for qemu fixes the following issues: * Fix bsc#1221812: * block: Reschedule query-block during qcow2 invalidation (bsc#1221812) * Fix bsc#1229007, CVE-2024-7409: * nbd/server: CVE-2024-7409: Close stray clients at server-stop (bsc#1229007) * nbd/server: CVE-2024-7409: Drop non-negotiating clients (bsc#1229007) * nbd/server: CVE-2024-7409: Cap default max-connections to 100 (bsc#1229007) * nbd/server: Plumb in new args to nbd_client_add() (bsc#1229007, CVE-2024-7409) * nbd: Minor style and typo fixes (bsc#1229007, CVE-2024-7409) * Update to version 8.2.6: Full backport lists (from the various releases) here: https://lore.kernel.org/qemu- devel/1721203806.547734.831464.nullmailer@tls.msk.ru/ Some of the upstream backports are: hw/nvme: fix number of PIDs for FDP RUH update sphinx/qapidoc: Fix to generate doc for explicit, unboxed arguments char- stdio: Restore blocking mode of stdout on exit virtio: remove virtio_tswap16s() call in vring_packed_event_read() virtio-pci: Fix the failure process in kvm_virtio_pci_vector_use_one() block: Parse filenames only when explicitly requested iotests/270: Don'tstore data-file with json: prefix in image iotests/244: Don't store data-file with protocol in image qcow2: Don't open data_file with BDRV_O_NO_IO (bsc#1227322, CVE-2024-4467) target/arm: Fix FJCVTZS vs flush-to-zero target/arm: Fix VCMLA Dd, Dn, Dm[idx] i386/cpu: fixup number of addressable IDs for processor cores in the physical package tests: Update our CI to use CentOS Stream 9 instead of 8 migration: Fix file migration with fdset tcg/loongarch64: Fix tcg_out_movi vs some pcrel pointers target/sparc: use signed denominator in sdiv helper linux-user: Make TARGET_NR_setgroups affect only the current thread accel/tcg: Fix typo causing tb-> page_addr[1] to not be recorded stdvga: fix screen blanking hw/audio/virtio-snd: Always use little endian audio format ui/gtk: Draw guest frame at refresh cycle virtio-net: drop too short packets early target/i386: fix size of EBP writeback in gen_enter() ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-60=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * qemu-hw-display-virtio-vga-8.2.6-1.1 * qemu-hw-usb-redirect-8.2.6-1.1 * qemu-debuginfo-8.2.6-1.1 * qemu-audio-spice-debuginfo-8.2.6-1.1 * qemu-hw-display-virtio-gpu-8.2.6-1.1 * qemu-hw-display-virtio-gpu-debuginfo-8.2.6-1.1 * qemu-ui-spice-core-8.2.6-1.1 * qemu-block-curl-debuginfo-8.2.6-1.1 * qemu-pr-helper-8.2.6-1.1 * qemu-tools-debuginfo-8.2.6-1.1 * qemu-ui-spice-core-debuginfo-8.2.6-1.1 * qemu-pr-helper-debuginfo-8.2.6-1.1 * qemu-img-8.2.6-1.1 * qemu-lang-8.2.6-1.1 * qemu-hw-display-qxl-debuginfo-8.2.6-1.1 * qemu-hw-display-qxl-8.2.6-1.1 * qemu-chardev-spice-debuginfo-8.2.6-1.1 * qemu-hw-usb-host-8.2.6-1.1 * qemu-block-iscsi-8.2.6-1.1 * qemu-block-ssh-8.2.6-1.1 *qemu-block-ssh-debuginfo-8.2.6-1.1 * qemu-8.2.6-1.1 * qemu-block-iscsi-debuginfo-8.2.6-1.1 * qemu-hw-display-virtio-gpu-pci-8.2.6-1.1 * qemu-tools-8.2.6-1.1 * qemu-hw-usb-host-debuginfo-8.2.6-1.1 * qemu-ui-opengl-8.2.6-1.1 * qemu-audio-spice-8.2.6-1.1 * qemu-guest-agent-8.2.6-1.1 * qemu-chardev-spice-8.2.6-1.1 * qemu-ksm-8.2.6-1.1 * qemu-debugsource-8.2.6-1.1 * qemu-img-debuginfo-8.2.6-1.1 * qemu-block-curl-8.2.6-1.1 * qemu-ui-opengl-debuginfo-8.2.6-1.1 * qemu-block-rbd-debuginfo-8.2.6-1.1 * qemu-hw-usb-redirect-debuginfo-8.2.6-1.1 * qemu-block-rbd-8.2.6-1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-8.2.6-1.1 * qemu-guest-agent-debuginfo-8.2.6-1.1 * qemu-hw-display-virtio-vga-debuginfo-8.2.6-1.1 * SUSE Linux Micro 6.0 (x86_64) * qemu-x86-8.2.6-1.1 * qemu-x86-debuginfo-8.2.6-1.1 * qemu-accel-tcg-x86-8.2.6-1.1 * qemu-accel-tcg-x86-debuginfo-8.2.6-1.1 * SUSE Linux Micro 6.0 (noarch) * qemu-vgabios-8.2.61.16.3_3_ga95067eb-1.1 * qemu-seabios-8.2.61.16.3_3_ga95067eb-1.1 * qemu-ipxe-8.2.6-1.1 * SUSE Linux Micro 6.0 (s390x) * qemu-s390x-debuginfo-8.2.6-1.1 * qemu-s390x-8.2.6-1.1 * SUSE Linux Micro 6.0 (aarch64) * qemu-arm-debuginfo-8.2.6-1.1 * qemu-arm-8.2.6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-4467.html * https://www.suse.com/security/cve/CVE-2024-7409.html * https://bugzilla.suse.com/show_bug.cgi?id=1221812 * https://bugzilla.suse.com/show_bug.cgi?id=1227322 * https://bugzilla.suse.com/show_bug.cgi?id=1229007 . SUSE has rolled out a critical update for QEMU, addressing severe vulnerabilities and glitches, crucial for maintaining system integrity.. SUSE Linux Micro,qemu security fix,important security update. . Severity: Important. LinuxSecurity.com Team
* bsc#1224132 * bsc#1229007 * bsc#1229929 * bsc#1230140 * bsc#1230834 . # Security update for qemu Announcement ID: SUSE-SU-2025:20076-1 Release Date: 2025-02-03T09:05:12Z Rating: important References: * bsc#1224132 * bsc#1229007 * bsc#1229929 * bsc#1230140 * bsc#1230834 * bsc#1230915 * bsc#1231519 Cross-References: * CVE-2024-4693 * CVE-2024-7409 * CVE-2024-8354 * CVE-2024-8612 CVSS scores: * CVE-2024-4693 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8354 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-8354 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8354 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8354 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8612 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-8612 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2024-8612 ( NVD ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has three fixes can now be installed. ## Description: This update for qemu fixes the following issues: * Bugfixes and CVEs: * hw/usb/hcd-ohci: Fix #1510, #303: pid not IN or OUT (bsc#1230834, CVE-2024-8354) * softmmu: Support concurrent bounce buffers (bsc#1230915, CVE-2024-8612) * system/physmem: Per-AddressSpace bounce buffering (bsc#1230915, CVE-2024-8612) * system/physmem: Propagate AddressSpace to MapClient helpers (bsc#1230915, CVE-2024-8612) * system/physmem: Replace qemu_mutex_lock() calls with QEMU_LOCK_GUARD (bsc#1230915,CVE-2024-8612) * Update version to 8.2.7 * Full changelog here: https://lore.kernel.org/qemu- devel/
* bsc#1224132 * bsc#1229007 * bsc#1229929 * bsc#1230140 * bsc#1230834 . # Security update for qemu Announcement ID: SUSE-SU-2025:20076-1 Release Date: 2025-02-03T09:05:12Z Rating: important References: * bsc#1224132 * bsc#1229007 * bsc#1229929 * bsc#1230140 * bsc#1230834 * bsc#1230915 * bsc#1231519 Cross-References: * CVE-2024-4693 * CVE-2024-7409 * CVE-2024-8354 * CVE-2024-8612 CVSS scores: * CVE-2024-4693 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8354 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-8354 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8354 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8354 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8612 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-8612 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2024-8612 ( NVD ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has three fixes can now be installed. ## Description: This update for qemu fixes the following issues: * Bugfixes and CVEs: * hw/usb/hcd-ohci: Fix #1510, #303: pid not IN or OUT (bsc#1230834, CVE-2024-8354) * softmmu: Support concurrent bounce buffers (bsc#1230915, CVE-2024-8612) * system/physmem: Per-AddressSpace bounce buffering (bsc#1230915, CVE-2024-8612) * system/physmem: Propagate AddressSpace to MapClient helpers (bsc#1230915, CVE-2024-8612) * system/physmem: Replace qemu_mutex_lock() calls with QEMU_LOCK_GUARD (bsc#1230915,CVE-2024-8612) * Update version to 8.2.7 * Full changelog here: https://lore.kernel.org/qemu- devel/
Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service or information leak. CVE-2023-1544 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4144-1
An update that solves three vulnerabilities and has two security fixes can now be installed.. # Security update for qemu Announcement ID: SUSE-SU-2025:0692-1 Release Date: 2025-02-24T14:21:31Z Rating: important References: * bsc#1219722 * bsc#1219733 * bsc#1222845 * bsc#1229007 * bsc#1230915 Cross-References: * CVE-2024-3447 * CVE-2024-7409 * CVE-2024-8612 CVSS scores: * CVE-2024-3447 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-3447 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-7409 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-7409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7409 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8612 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-8612 ( SUSE ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2024-8612 ( NVD ): 3.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for qemu fixes the following issues: * CVE-2024-8612: Fixed information leak in virtio devices (bsc#1230915). * CVE-2024-7409: Fixed denial of service via improper synchronization in QEMU NBD Server during socket closure (bsc#1229007). * CVE-2024-3447: Fixed heap buffer overflow in sdhci_write_dataport() (bsc#1222845). Other fixes: * Fix ipxe buildwith new binutils (bsc#1219733, bsc#1219722). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-692=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-692=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-692=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-692=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-692=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-692=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-692=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-692=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * qemu-ui-curses-5.2.0-150300.135.1 * qemu-audio-pa-debuginfo-5.2.0-150300.135.1 * qemu-ivshmem-tools-debuginfo-5.2.0-150300.135.1 * qemu-block-iscsi-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-debuginfo-5.2.0-150300.135.1 * qemu-lang-5.2.0-150300.135.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-smartcard-debuginfo-5.2.0-150300.135.1 * qemu-block-dmg-5.2.0-150300.135.1 * qemu-extra-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-block-gluster-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * qemu-block-dmg-debuginfo-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-vhost-user-gpu-debuginfo-5.2.0-150300.135.1 *qemu-x86-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ivshmem-tools-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-ppc-debuginfo-5.2.0-150300.135.1 * qemu-linux-user-5.2.0-150300.135.1 * qemu-audio-alsa-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-extra-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-smartcard-5.2.0-150300.135.1 * qemu-chardev-baum-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-block-curl-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-5.2.0-150300.135.1 * qemu-block-ssh-debuginfo-5.2.0-150300.135.1 * qemu-s390x-5.2.0-150300.135.1 * qemu-vhost-user-gpu-5.2.0-150300.135.1 * qemu-ui-gtk-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-s390x-debuginfo-5.2.0-150300.135.1 * qemu-linux-user-debuginfo-5.2.0-150300.135.1 * qemu-hw-s390x-virtio-gpu-ccw-5.2.0-150300.135.1 * qemu-block-iscsi-5.2.0-150300.135.1 * qemu-arm-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-block-curl-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-ui-gtk-debuginfo-5.2.0-150300.135.1 * qemu-ksm-5.2.0-150300.135.1 * qemu-ui-spice-app-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-x86-5.2.0-150300.135.1 * qemu-ui-curses-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-app-5.2.0-150300.135.1 *qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-block-gluster-debuginfo-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-chardev-baum-debuginfo-5.2.0-150300.135.1 * qemu-testsuite-5.2.0-150300.135.1 * qemu-linux-user-debugsource-5.2.0-150300.135.1 * qemu-block-nfs-debuginfo-5.2.0-150300.135.1 * qemu-block-ssh-5.2.0-150300.135.1 * qemu-ppc-5.2.0-150300.135.1 * qemu-audio-pa-5.2.0-150300.135.1 * qemu-block-nfs-5.2.0-150300.135.1 * openSUSE Leap 15.3 (s390x x86_64 i586) * qemu-kvm-5.2.0-150300.135.1 * openSUSE Leap 15.3 (noarch) * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-microvm-5.2.0-150300.135.1 * qemu-sgabios-8-150300.135.1 * qemu-skiboot-5.2.0-150300.135.1 * qemu-SLOF-5.2.0-150300.135.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64) * qemu-block-rbd-5.2.0-150300.135.1 * qemu-block-rbd-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * qemu-ui-curses-5.2.0-150300.135.1 * qemu-block-iscsi-debuginfo-5.2.0-150300.135.1 * qemu-lang-5.2.0-150300.135.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-chardev-baum-5.2.0-150300.135.1 * qemu-block-curl-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-block-rbd-5.2.0-150300.135.1 * qemu-block-ssh-debuginfo-5.2.0-150300.135.1 * qemu-ui-gtk-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-block-iscsi-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-block-curl-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-ui-gtk-debuginfo-5.2.0-150300.135.1 * qemu-ksm-5.2.0-150300.135.1 * qemu-ui-spice-app-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-ui-curses-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-app-5.2.0-150300.135.1 * qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-chardev-baum-debuginfo-5.2.0-150300.135.1 * qemu-block-rbd-debuginfo-5.2.0-150300.135.1 * qemu-block-ssh-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64) * qemu-arm-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * qemu-audio-pa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-5.2.0-150300.135.1 * qemu-kvm-5.2.0-150300.135.1 * qemu-x86-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 * qemu-audio-pa-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * qemu-ui-curses-5.2.0-150300.135.1 * qemu-block-iscsi-debuginfo-5.2.0-150300.135.1 *qemu-lang-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-chardev-baum-5.2.0-150300.135.1 * qemu-block-curl-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-block-rbd-5.2.0-150300.135.1 * qemu-block-ssh-debuginfo-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-block-iscsi-5.2.0-150300.135.1 * qemu-block-curl-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-ksm-5.2.0-150300.135.1 * qemu-ui-curses-debuginfo-5.2.0-150300.135.1 * qemu-chardev-baum-debuginfo-5.2.0-150300.135.1 * qemu-block-rbd-debuginfo-5.2.0-150300.135.1 * qemu-block-ssh-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64) * qemu-arm-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le x86_64) * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ui-gtk-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-app-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-app-5.2.0-150300.135.1 * qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-ui-gtk-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * qemu-skiboot-5.2.0-150300.135.1 * qemu-SLOF-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (ppc64le) * qemu-ppc-5.2.0-150300.135.1 * qemu-ppc-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (s390x x86_64) * qemu-kvm-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (s390x) * qemu-hw-s390x-virtio-gpu-ccw-5.2.0-150300.135.1 * qemu-s390x-5.2.0-150300.135.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-5.2.0-150300.135.1 * qemu-s390x-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (x86_64) * qemu-audio-pa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-5.2.0-150300.135.1 * qemu-x86-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 * qemu-audio-pa-5.2.0-150300.135.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * qemu-ui-curses-5.2.0-150300.135.1 * qemu-block-iscsi-debuginfo-5.2.0-150300.135.1 * qemu-lang-5.2.0-150300.135.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-chardev-baum-5.2.0-150300.135.1 * qemu-block-curl-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 *qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-block-rbd-5.2.0-150300.135.1 * qemu-block-ssh-debuginfo-5.2.0-150300.135.1 * qemu-ui-gtk-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-block-iscsi-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-block-curl-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-ui-gtk-debuginfo-5.2.0-150300.135.1 * qemu-ksm-5.2.0-150300.135.1 * qemu-ui-spice-app-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-ui-curses-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-app-5.2.0-150300.135.1 * qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-chardev-baum-debuginfo-5.2.0-150300.135.1 * qemu-block-rbd-debuginfo-5.2.0-150300.135.1 * qemu-block-ssh-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * qemu-skiboot-5.2.0-150300.135.1 * qemu-SLOF-5.2.0-150300.135.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le) * qemu-ppc-5.2.0-150300.135.1 * qemu-ppc-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * qemu-audio-pa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-5.2.0-150300.135.1 * qemu-kvm-5.2.0-150300.135.1 * qemu-x86-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 * qemu-audio-pa-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-5.2.0-150300.135.1 *SUSE Enterprise Storage 7.1 (aarch64 x86_64) * qemu-ui-curses-5.2.0-150300.135.1 * qemu-block-iscsi-debuginfo-5.2.0-150300.135.1 * qemu-lang-5.2.0-150300.135.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-chardev-baum-5.2.0-150300.135.1 * qemu-block-curl-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-block-rbd-5.2.0-150300.135.1 * qemu-block-ssh-debuginfo-5.2.0-150300.135.1 * qemu-ui-gtk-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-block-iscsi-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-block-curl-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-ui-gtk-debuginfo-5.2.0-150300.135.1 * qemu-ksm-5.2.0-150300.135.1 * qemu-ui-spice-app-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-ui-curses-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-app-5.2.0-150300.135.1 * qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-chardev-baum-debuginfo-5.2.0-150300.135.1 * qemu-block-rbd-debuginfo-5.2.0-150300.135.1 * qemu-block-ssh-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * SUSE Enterprise Storage 7.1 (aarch64) * qemu-arm-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * SUSE Enterprise Storage 7.1 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.135.1 *qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * SUSE Enterprise Storage 7.1 (x86_64) * qemu-audio-pa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-debuginfo-5.2.0-150300.135.1 * qemu-audio-alsa-5.2.0-150300.135.1 * qemu-kvm-5.2.0-150300.135.1 * qemu-x86-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 * qemu-audio-pa-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-pci-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * qemu-tools-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.1 (aarch64) * qemu-arm-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.1 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * SUSE Linux Enterprise Micro 5.1 (s390x) * qemu-s390x-debuginfo-5.2.0-150300.135.1 * qemu-s390x-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.1 (x86_64) * qemu-x86-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 *qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.2 (aarch64) * qemu-arm-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.2 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * SUSE Linux Enterprise Micro 5.2 (s390x) * qemu-s390x-debuginfo-5.2.0-150300.135.1 * qemu-s390x-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * qemu-x86-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * qemu-ui-opengl-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.135.1 * qemu-hw-usb-redirect-5.2.0-150300.135.1 * qemu-tools-debuginfo-5.2.0-150300.135.1 * qemu-ui-opengl-5.2.0-150300.135.1 * qemu-hw-display-qxl-5.2.0-150300.135.1 * qemu-hw-display-virtio-vga-5.2.0-150300.135.1 * qemu-chardev-spice-5.2.0-150300.135.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.135.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.135.1 * qemu-debugsource-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.135.1 * qemu-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-debuginfo-5.2.0-150300.135.1 * qemu-guest-agent-5.2.0-150300.135.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.135.1 * qemu-5.2.0-150300.135.1 * qemu-audio-spice-debuginfo-5.2.0-150300.135.1 * qemu-tools-5.2.0-150300.135.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.135.1 * qemu-ui-spice-core-5.2.0-150300.135.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.135.1 * qemu-audio-spice-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64) * qemu-arm-5.2.0-150300.135.1 * qemu-arm-debuginfo-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.135.1 * qemu-vgabios-1.14.0_0_g155821a-150300.135.1 * qemu-ipxe-1.0.0+-150300.135.1 * qemu-sgabios-8-150300.135.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (s390x) * qemu-s390x-debuginfo-5.2.0-150300.135.1 * qemu-s390x-5.2.0-150300.135.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * qemu-x86-5.2.0-150300.135.1 * qemu-x86-debuginfo-5.2.0-150300.135.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3447.html * https://www.suse.com/security/cve/CVE-2024-7409.html * https://www.suse.com/security/cve/CVE-2024-8612.html * https://bugzilla.suse.com/show_bug.cgi?id=1219722 * https://bugzilla.suse.com/show_bug.cgi?id=1219733 * https://bugzilla.suse.com/show_bug.cgi?id=1222845 * https://bugzilla.suse.com/show_bug.cgi?id=1229007 * https://bugzilla.suse.com/show_bug.cgi?id=1230915 . This release resolves various bugs in qemu, notably serious memory leaks and vulnerabilities leading to service interruptions. Apply the patch now!. SUSE Security Update,QEMU Advisory,OpenSUSE QEMU Fix,Security Patch Instructions. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.