Описание
Security update for qemu
This update for qemu fixes the following issues
- CVE-2026-3886: QEMU calc_image_hostmem Integer Overflow Local Privilege Escalation Vulnerability (bsc#1268061).
- CVE-2026-48004: heap use-after-free race condition allows a DoS by an unprivileged guest user (bsc#1270133).
- CVE-2026-48914: qemu-kvm: Heap Buffer Overflow in virtio-blk SCSI Request Handling (bsc#1268794).
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15 SP7
qemu-img-9.2.4-150700.3.23.1
qemu-pr-helper-9.2.4-150700.3.23.1
qemu-tools-9.2.4-150700.3.23.1
qemu-vmsr-helper-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
qemu-SLOF-9.2.4-150700.3.23.1
qemu-accel-qtest-9.2.4-150700.3.23.1
qemu-arm-9.2.4-150700.3.23.1
qemu-audio-jack-9.2.4-150700.3.23.1
qemu-audio-oss-9.2.4-150700.3.23.1
qemu-block-dmg-9.2.4-150700.3.23.1
qemu-extra-9.2.4-150700.3.23.1
qemu-hw-display-virtio-gpu-9.2.4-150700.3.23.1
qemu-hw-display-virtio-gpu-pci-9.2.4-150700.3.23.1
qemu-hw-s390x-virtio-gpu-ccw-9.2.4-150700.3.23.1
qemu-hw-usb-smartcard-9.2.4-150700.3.23.1
qemu-ivshmem-tools-9.2.4-150700.3.23.1
qemu-linux-user-9.2.4-150700.3.23.1
qemu-microvm-9.2.4-150700.3.23.1
qemu-ppc-9.2.4-150700.3.23.1
qemu-s390x-9.2.4-150700.3.23.1
qemu-skiboot-9.2.4-150700.3.23.1
qemu-vhost-user-gpu-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP7
qemu-9.2.4-150700.3.23.1
qemu-SLOF-9.2.4-150700.3.23.1
qemu-accel-tcg-x86-9.2.4-150700.3.23.1
qemu-arm-9.2.4-150700.3.23.1
qemu-audio-alsa-9.2.4-150700.3.23.1
qemu-audio-dbus-9.2.4-150700.3.23.1
qemu-audio-pa-9.2.4-150700.3.23.1
qemu-audio-pipewire-9.2.4-150700.3.23.1
qemu-audio-spice-9.2.4-150700.3.23.1
qemu-block-curl-9.2.4-150700.3.23.1
qemu-block-iscsi-9.2.4-150700.3.23.1
qemu-block-nfs-9.2.4-150700.3.23.1
qemu-block-rbd-9.2.4-150700.3.23.1
qemu-block-ssh-9.2.4-150700.3.23.1
qemu-chardev-baum-9.2.4-150700.3.23.1
qemu-chardev-spice-9.2.4-150700.3.23.1
qemu-guest-agent-9.2.4-150700.3.23.1
qemu-headless-9.2.4-150700.3.23.1
qemu-hw-display-qxl-9.2.4-150700.3.23.1
qemu-hw-display-virtio-gpu-9.2.4-150700.3.23.1
qemu-hw-display-virtio-gpu-pci-9.2.4-150700.3.23.1
qemu-hw-display-virtio-vga-9.2.4-150700.3.23.1
qemu-hw-s390x-virtio-gpu-ccw-9.2.4-150700.3.23.1
qemu-hw-usb-host-9.2.4-150700.3.23.1
qemu-hw-usb-redirect-9.2.4-150700.3.23.1
qemu-ipxe-9.2.4-150700.3.23.1
qemu-ksm-9.2.4-150700.3.23.1
qemu-lang-9.2.4-150700.3.23.1
qemu-ppc-9.2.4-150700.3.23.1
qemu-s390x-9.2.4-150700.3.23.1
qemu-seabios-9.2.41.16.3_3_g3d33c746-150700.3.23.1
qemu-skiboot-9.2.4-150700.3.23.1
qemu-spice-9.2.4-150700.3.23.1
qemu-ui-curses-9.2.4-150700.3.23.1
qemu-ui-dbus-9.2.4-150700.3.23.1
qemu-ui-gtk-9.2.4-150700.3.23.1
qemu-ui-opengl-9.2.4-150700.3.23.1
qemu-ui-spice-app-9.2.4-150700.3.23.1
qemu-ui-spice-core-9.2.4-150700.3.23.1
qemu-vgabios-9.2.41.16.3_3_g3d33c746-150700.3.23.1
qemu-x86-9.2.4-150700.3.23.1
Ссылки
- Link for SUSE-SU-2026:3038-1
- E-Mail link for SUSE-SU-2026:3038-1
- SUSE Security Ratings
- SUSE Bug 1268061
- SUSE Bug 1268794
- SUSE Bug 1270133
- SUSE CVE CVE-2026-3886 page
- SUSE CVE CVE-2026-48004 page
- SUSE CVE CVE-2026-48914 page
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-img-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-pr-helper-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-tools-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-vmsr-helper-9.2.4-150700.3.23.1
Ссылки
- CVE-2026-3886
- SUSE Bug 1268061
Описание
unknown
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-img-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-pr-helper-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-tools-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-vmsr-helper-9.2.4-150700.3.23.1
Ссылки
- CVE-2026-48004
- SUSE Bug 1270133
Описание
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-img-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-pr-helper-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-tools-9.2.4-150700.3.23.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:qemu-vmsr-helper-9.2.4-150700.3.23.1
Ссылки
- CVE-2026-48914
- SUSE Bug 1268794