SUSE alert SUSE-SU-2026:0070-1 (qemu)
| From: | SLE-SECURITY-UPDATES <null@suse.de> | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2026:0070-1: important: Security update for qemu | |
| Date: | Thu, 08 Jan 2026 20:30:17 -0000 | |
| Message-ID: | <176790421756.22173.5576018118880668703@smelt2.prg2.suse.org> |
# Security update for qemu Announcement ID: SUSE-SU-2026:0070-1 Release Date: 2026-01-08T13:22:00Z Rating: important References: * bsc#1209554 * bsc#1227397 Cross-References: * CVE-2023-1544 * CVE-2024-6505 CVSS scores: * CVE-2023-1544 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H * CVE-2023-1544 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H * CVE-2023-1544 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-6505 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-6505 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H * CVE-2024-6505 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for qemu fixes the following issues: * CVE-2024-6505: Fixed queue index out-of-bounds access in software RSS (bsc#1227397) * CVE-2023-1544: Fixed out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-70=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-70=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-70=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * qemu-s390x-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-pci-5.2.0-150300.138.1 * qemu-tools-5.2.0-150300.138.1 * qemu-block-dmg-5.2.0-150300.138.1 * qemu-extra-5.2.0-150300.138.1 * qemu-ui-gtk-debuginfo-5.2.0-150300.138.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.138.1 * qemu-testsuite-5.2.0-150300.138.2 * qemu-block-dmg-debuginfo-5.2.0-150300.138.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.138.1 * qemu-hw-usb-smartcard-debuginfo-5.2.0-150300.138.1 * qemu-ui-opengl-5.2.0-150300.138.1 * qemu-ui-spice-app-5.2.0-150300.138.1 * qemu-audio-spice-debuginfo-5.2.0-150300.138.1 * qemu-ui-gtk-5.2.0-150300.138.1 * qemu-linux-user-debuginfo-5.2.0-150300.138.1 * qemu-guest-agent-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-5.2.0-150300.138.1 * qemu-5.2.0-150300.138.1 * qemu-arm-5.2.0-150300.138.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.138.1 * qemu-audio-pa-debuginfo-5.2.0-150300.138.1 * qemu-chardev-baum-debuginfo-5.2.0-150300.138.1 * qemu-block-iscsi-5.2.0-150300.138.1 * qemu-guest-agent-5.2.0-150300.138.1 * qemu-ivshmem-tools-debuginfo-5.2.0-150300.138.1 * qemu-block-gluster-5.2.0-150300.138.1 * qemu-s390x-debuginfo-5.2.0-150300.138.1 * qemu-ui-curses-debuginfo-5.2.0-150300.138.1 * qemu-ui-spice-core-5.2.0-150300.138.1 * qemu-audio-alsa-5.2.0-150300.138.1 * qemu-vhost-user-gpu-debuginfo-5.2.0-150300.138.1 * qemu-lang-5.2.0-150300.138.1 * qemu-block-nfs-5.2.0-150300.138.1 * qemu-block-ssh-debuginfo-5.2.0-150300.138.1 * qemu-hw-s390x-virtio-gpu-ccw-5.2.0-150300.138.1 * qemu-ksm-5.2.0-150300.138.1 * qemu-arm-debuginfo-5.2.0-150300.138.1 * qemu-block-curl-debuginfo-5.2.0-150300.138.1 * qemu-x86-5.2.0-150300.138.1 * qemu-ui-spice-app-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.138.1 * qemu-chardev-spice-5.2.0-150300.138.1 * qemu-audio-pa-5.2.0-150300.138.1 * qemu-hw-display-qxl-5.2.0-150300.138.1 * qemu-linux-user-debugsource-5.2.0-150300.138.1 * qemu-audio-alsa-debuginfo-5.2.0-150300.138.1 * qemu-debugsource-5.2.0-150300.138.1 * qemu-debuginfo-5.2.0-150300.138.1 * qemu-extra-debuginfo-5.2.0-150300.138.1 * qemu-x86-debuginfo-5.2.0-150300.138.1 * qemu-block-nfs-debuginfo-5.2.0-150300.138.1 * qemu-ppc-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.138.1 * qemu-ivshmem-tools-5.2.0-150300.138.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.138.1 * qemu-block-ssh-5.2.0-150300.138.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.138.1 * qemu-ppc-5.2.0-150300.138.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-vga-5.2.0-150300.138.1 * qemu-tools-debuginfo-5.2.0-150300.138.1 * qemu-block-gluster-debuginfo-5.2.0-150300.138.1 * qemu-block-iscsi-debuginfo-5.2.0-150300.138.1 * qemu-audio-spice-5.2.0-150300.138.1 * qemu-hw-usb-redirect-5.2.0-150300.138.1 * qemu-block-curl-5.2.0-150300.138.1 * qemu-vhost-user-gpu-5.2.0-150300.138.1 * qemu-hw-usb-smartcard-5.2.0-150300.138.1 * qemu-linux-user-5.2.0-150300.138.1 * qemu-chardev-baum-5.2.0-150300.138.1 * qemu-ui-curses-5.2.0-150300.138.1 * openSUSE Leap 15.3 (s390x x86_64 i586) * qemu-kvm-5.2.0-150300.138.1 * openSUSE Leap 15.3 (noarch) * qemu-microvm-5.2.0-150300.138.1 * qemu-SLOF-5.2.0-150300.138.1 * qemu-seabios-1.14.0_0_g155821a-150300.138.1 * qemu-skiboot-5.2.0-150300.138.1 * qemu-sgabios-8-150300.138.1 * qemu-vgabios-1.14.0_0_g155821a-150300.138.1 * qemu-ipxe-1.0.0+-150300.138.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64) * qemu-block-rbd-debuginfo-5.2.0-150300.138.1 * qemu-block-rbd-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * qemu-tools-5.2.0-150300.138.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.138.1 * qemu-ui-opengl-5.2.0-150300.138.1 * qemu-audio-spice-debuginfo-5.2.0-150300.138.1 * qemu-guest-agent-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.138.1 * qemu-5.2.0-150300.138.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.138.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.138.1 * qemu-guest-agent-5.2.0-150300.138.1 * qemu-ui-spice-core-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.138.1 * qemu-chardev-spice-5.2.0-150300.138.1 * qemu-hw-display-qxl-5.2.0-150300.138.1 * qemu-debugsource-5.2.0-150300.138.1 * qemu-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.138.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-vga-5.2.0-150300.138.1 * qemu-tools-debuginfo-5.2.0-150300.138.1 * qemu-audio-spice-5.2.0-150300.138.1 * qemu-hw-usb-redirect-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro 5.2 (aarch64) * qemu-arm-debuginfo-5.2.0-150300.138.1 * qemu-arm-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro 5.2 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.138.1 * qemu-sgabios-8-150300.138.1 * qemu-vgabios-1.14.0_0_g155821a-150300.138.1 * qemu-ipxe-1.0.0+-150300.138.1 * SUSE Linux Enterprise Micro 5.2 (s390x) * qemu-s390x-5.2.0-150300.138.1 * qemu-s390x-debuginfo-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * qemu-x86-5.2.0-150300.138.1 * qemu-x86-debuginfo-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * qemu-tools-5.2.0-150300.138.1 * qemu-hw-usb-redirect-debuginfo-5.2.0-150300.138.1 * qemu-ui-opengl-5.2.0-150300.138.1 * qemu-audio-spice-debuginfo-5.2.0-150300.138.1 * qemu-guest-agent-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-qxl-debuginfo-5.2.0-150300.138.1 * qemu-5.2.0-150300.138.1 * qemu-ui-opengl-debuginfo-5.2.0-150300.138.1 * qemu-chardev-spice-debuginfo-5.2.0-150300.138.1 * qemu-guest-agent-5.2.0-150300.138.1 * qemu-ui-spice-core-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-debuginfo-5.2.0-150300.138.1 * qemu-chardev-spice-5.2.0-150300.138.1 * qemu-hw-display-qxl-5.2.0-150300.138.1 * qemu-debugsource-5.2.0-150300.138.1 * qemu-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-gpu-5.2.0-150300.138.1 * qemu-ui-spice-core-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-vga-debuginfo-5.2.0-150300.138.1 * qemu-hw-display-virtio-vga-5.2.0-150300.138.1 * qemu-tools-debuginfo-5.2.0-150300.138.1 * qemu-audio-spice-5.2.0-150300.138.1 * qemu-hw-usb-redirect-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64) * qemu-arm-debuginfo-5.2.0-150300.138.1 * qemu-arm-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * qemu-seabios-1.14.0_0_g155821a-150300.138.1 * qemu-sgabios-8-150300.138.1 * qemu-vgabios-1.14.0_0_g155821a-150300.138.1 * qemu-ipxe-1.0.0+-150300.138.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (s390x) * qemu-s390x-5.2.0-150300.138.1 * qemu-s390x-debuginfo-5.2.0-150300.138.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * qemu-x86-5.2.0-150300.138.1 * qemu-x86-debuginfo-5.2.0-150300.138.1 ## References: * https://www.suse.com/security/cve/CVE-2023-1544.html * https://www.suse.com/security/cve/CVE-2024-6505.html * https://bugzilla.suse.com/show_bug.cgi?id=1209554 * https://bugzilla.suse.com/show_bug.cgi?id=1227397
Attachment: None (type=text/html)
(HTML attachment elided)
