Количество 53
Количество 53
ALT-PU-2023-5241
ALT-PU-2023-5241: package `qemu` update to version 8.0.4-alt1.p10
ROS-20240401-01
Множественные уязвимости qemu
GHSA-x9c6-9g9w-hg73
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service.
GHSA-835p-c6x8-xh5f
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the `out_sg` variable could be used to read a part of process memory and send it to the wire, causing an information leak.
BDU:2024-04886
Уязвимость интерфейса virtio-net сервера QEMU, позволяющая нарушителю вызвать утечку информации
BDU:2024-00308
Уязвимость функции qemu_clipboard_request() встроенного сервера VNC эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2024:3229-1
Security update for qemu
RLSA-2025:4492
Moderate: qemu-kvm security update
ELSA-2025-4492
ELSA-2025-4492: qemu-kvm security update (MODERATE)
SUSE-SU-2024:1438-1
Security update for qemu
ALT-PU-2024-3359
ALT-PU-2024-3359: package `qemu` update to version 8.2.1-alt1
SUSE-SU-2024:1394-1
Security update for qemu
SUSE-SU-2024:1103-1
Security update for qemu
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ALT-PU-2023-5241 ALT-PU-2023-5241: package `qemu` update to version 8.0.4-alt1.p10 | CVSS3: 7.5 | около 3 лет назад | ||
ROS-20240401-01 Множественные уязвимости qemu | CVSS3: 10 | больше 2 лет назад | ||
GHSA-x9c6-9g9w-hg73 A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a NULL pointer dereference. This could allow a malicious authenticated VNC client to crash QEMU and trigger a denial of service. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-835p-c6x8-xh5f A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the `out_sg` variable could be used to read a part of process memory and send it to the wire, causing an information leak. | CVSS3: 4.9 | 0% Низкий | больше 2 лет назад | |
BDU:2024-04886 Уязвимость интерфейса virtio-net сервера QEMU, позволяющая нарушителю вызвать утечку информации | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
BDU:2024-00308 Уязвимость функции qemu_clipboard_request() встроенного сервера VNC эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 6.5 | 1% Низкий | почти 3 года назад | |
SUSE-SU-2024:3229-1 Security update for qemu | около 2 лет назад | |||
RLSA-2025:4492 Moderate: qemu-kvm security update | около 1 года назад | |||
ELSA-2025-4492 ELSA-2025-4492: qemu-kvm security update (MODERATE) | больше 1 года назад | |||
SUSE-SU-2024:1438-1 Security update for qemu | больше 2 лет назад | |||
ALT-PU-2024-3359 ALT-PU-2024-3359: package `qemu` update to version 8.2.1-alt1 | CVSS3: 6.5 | больше 2 лет назад | ||
SUSE-SU-2024:1394-1 Security update for qemu | больше 2 лет назад | |||
SUSE-SU-2024:1103-1 Security update for qemu | больше 2 лет назад |
Уязвимостей на страницу