Описание
Security update for qemu
This update for qemu fixes the following issues:
Update to version 10.0.11.
Security issues fixed:
- CVE-2026-3886: integer overflow leading to privilege escalation due to lack of proper validation of user-supplied data in the virtio-gpu driver (bsc#1268061).
- CVE-2026-48914: heap buffer overflow due to improper size validation in virtio-blk SCSI request handling (bsc#1268794).
- CVE-2026-48004: heap use-after-free race condition due to missing rename lock in v9fs_co_readdir_many (bsc#1270133).
Other updates and bugfixes:
- Version 10.0.11:
- Full backport list here: https://lore.kernel.org/qemu-devel/20260627082646.D825717AB67@think4mjt.localdomain/
- Version 10.0.10:
- Full backport list here: https://lore.kernel.org/qemu-devel/20260528061820.CEE521691A9@think4mjt.localdomain/
- ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279).
- i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266).
- i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266).
- update Linux headers to v6.16-rc3 (jsc#PED-9266).
- i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266).
- i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266).
- [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023).
Список пакетов
openSUSE Leap 16.0
qemu-10.0.11-160000.1.1
qemu-SLOF-10.0.11-160000.1.1
qemu-accel-qtest-10.0.11-160000.1.1
qemu-arm-10.0.11-160000.1.1
qemu-audio-alsa-10.0.11-160000.1.1
qemu-audio-dbus-10.0.11-160000.1.1
qemu-audio-jack-10.0.11-160000.1.1
qemu-audio-oss-10.0.11-160000.1.1
qemu-audio-pa-10.0.11-160000.1.1
qemu-audio-pipewire-10.0.11-160000.1.1
qemu-audio-spice-10.0.11-160000.1.1
qemu-block-curl-10.0.11-160000.1.1
qemu-block-dmg-10.0.11-160000.1.1
qemu-block-iscsi-10.0.11-160000.1.1
qemu-block-nfs-10.0.11-160000.1.1
qemu-block-rbd-10.0.11-160000.1.1
qemu-block-ssh-10.0.11-160000.1.1
qemu-chardev-baum-10.0.11-160000.1.1
qemu-chardev-spice-10.0.11-160000.1.1
qemu-doc-10.0.11-160000.1.1
qemu-extra-10.0.11-160000.1.1
qemu-guest-agent-10.0.11-160000.1.1
qemu-headless-10.0.11-160000.1.1
qemu-hw-display-qxl-10.0.11-160000.1.1
qemu-hw-display-virtio-gpu-10.0.11-160000.1.1
qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1
qemu-hw-display-virtio-vga-10.0.11-160000.1.1
qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1
qemu-hw-usb-host-10.0.11-160000.1.1
qemu-hw-usb-redirect-10.0.11-160000.1.1
qemu-hw-usb-smartcard-10.0.11-160000.1.1
qemu-img-10.0.11-160000.1.1
qemu-ipxe-10.0.11-160000.1.1
qemu-ivshmem-tools-10.0.11-160000.1.1
qemu-ksm-10.0.11-160000.1.1
qemu-lang-10.0.11-160000.1.1
qemu-linux-user-10.0.11-160000.1.1
qemu-microvm-10.0.11-160000.1.1
qemu-ppc-10.0.11-160000.1.1
qemu-pr-helper-10.0.11-160000.1.1
qemu-s390x-10.0.11-160000.1.1
qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1
qemu-skiboot-10.0.11-160000.1.1
qemu-spice-10.0.11-160000.1.1
qemu-tools-10.0.11-160000.1.1
qemu-ui-curses-10.0.11-160000.1.1
qemu-ui-dbus-10.0.11-160000.1.1
qemu-ui-gtk-10.0.11-160000.1.1
qemu-ui-opengl-10.0.11-160000.1.1
qemu-ui-spice-app-10.0.11-160000.1.1
qemu-ui-spice-core-10.0.11-160000.1.1
qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1
qemu-vhost-user-gpu-10.0.11-160000.1.1
qemu-vmsr-helper-10.0.11-160000.1.1
qemu-x86-10.0.11-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1199023
- SUSE Bug 1268061
- SUSE Bug 1268279
- SUSE Bug 1268794
- SUSE Bug 1270133
- SUSE CVE CVE-2026-3886 page
- SUSE CVE CVE-2026-48004 page
- SUSE CVE CVE-2026-48914 page
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:qemu-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-SLOF-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-accel-qtest-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-arm-10.0.11-160000.1.1
Ссылки
- CVE-2026-3886
- SUSE Bug 1268061
Описание
unknown
Затронутые продукты
openSUSE Leap 16.0:qemu-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-SLOF-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-accel-qtest-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-arm-10.0.11-160000.1.1
Ссылки
- CVE-2026-48004
- SUSE Bug 1270133
Описание
A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a malformed virtio-blk SCSI request, leading to an out-of-bounds write in the host heap memory and a potential denial of service (DoS) for the QEMU process.
Затронутые продукты
openSUSE Leap 16.0:qemu-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-SLOF-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-accel-qtest-10.0.11-160000.1.1
openSUSE Leap 16.0:qemu-arm-10.0.11-160000.1.1
Ссылки
- CVE-2026-48914
- SUSE Bug 1268794