Описание
Security update for qemu
This update for qemu fixes the following issues:
- CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a 12-byte information leak when processing specially crafted VMDK files (bsc#1258509).
- CVE-2026-3195: heap buffer overflow when reading input audio in the virtio-snd device input callback due to
insufficient checks in
virtio_snd_pcm_in_cb(bsc#1259080). - CVE-2026-3196: integer overflow in the virtio-snd device via PCM_INFO requests from the guest leads to unbounded memory allocation and host denial-of-service (bsc#1259079).
- CVE-2026-3842: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host OOB write (bsc#1262089).
Список пакетов
Image SLES15-SP7-EC2-ECS-HVM
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Package Hub 15 SP7
SUSE Linux Enterprise Module for Server Applications 15 SP7
Ссылки
- Link for SUSE-SU-2026:2385-1
- E-Mail link for SUSE-SU-2026:2385-1
- SUSE Security Ratings
- SUSE Bug 1199023
- SUSE Bug 1258509
- SUSE Bug 1259079
- SUSE Bug 1259080
- SUSE Bug 1262089
- SUSE CVE CVE-2026-2243 page
- SUSE CVE CVE-2026-3195 page
- SUSE CVE CVE-2026-3196 page
- SUSE CVE CVE-2026-3842 page
Описание
A flaw was found in QEMU. A specially crafted VMDK image could trigger an out-of-bounds read vulnerability, potentially leading to a 12-byte leak of sensitive information or a denial of service condition (DoS).
Затронутые продукты
Ссылки
- CVE-2026-2243
- SUSE Bug 1258509
Описание
A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` function did not check whether the iov could fit the data buffer, potentially leading to a heap out-of-bounds write. This issue exists due to an incomplete fix for CVE-2024-7730.
Затронутые продукты
Ссылки
- CVE-2026-3195
- SUSE Bug 1259080
Описание
An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious guest can provide out-of-bounds stream counts, potentially leading to unbounded memory allocation on the host and a denial of service condition.
Затронутые продукты
Ссылки
- CVE-2026-3196
- SUSE Bug 1259079
Описание
unknown
Затронутые продукты
Ссылки
- CVE-2026-3842
- SUSE Bug 1262089