gpp_maybe
Security update for qemu
SUSE-SLE-Module-Basesystem-15-SP5-2024-1103
This update for qemu fixes the following issues: - CVE-2024-26327: Fixed buffer overflow via invalid SR/IOV NumVFs value (bsc#1220062). - CVE-2024-24474: Fixed integer overflow results in buffer overflow via SCSI command (bsc#1220134). - CVE-2023-6693: Fixed stack buffer overflow in virtio_net_flush_tx() (bsc#1218484). - CVE-2023-1544: Fixed out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554). - CVE-2024-26328: Fixed invalid NumVFs value handled in NVME SR/IOV implementation (bsc#1220065). The following non-security bug was fixed: - Removing in-use mediated device should fail with error message instead of hang (bsc#1205316).
-
Release DateApr 3 2024
-
ReferencesBugzilla: 1220062, 1205316, 1220134, 1218484, 1209554, 1220065
CVEs: CVE-2024-26328, CVE-2023-1544, CVE-2024-24474, CVE-2023-6693, CVE-2024-26327 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Basesystem Module 15.5 aarch64
-
Packagesqemu
Machine emulator and virtualizerqemu-tools7.1.0-150500.49.12.1 lock src
Tools for QEMU7.1.0-150500.49.12.1 lock rpm
Basesystem Module 15.5 s390x
-
Packagesqemu
Machine emulator and virtualizerqemu-tools7.1.0-150500.49.12.1 lock src
Tools for QEMU7.1.0-150500.49.12.1 lock rpm
Basesystem Module 15.5 x86_64
-
Packagesqemu
Machine emulator and virtualizerqemu-tools7.1.0-150500.49.12.1 lock src
Tools for QEMU7.1.0-150500.49.12.1 lock rpm
Basesystem Module 15.5 ppc64le
-
Packagesqemu
Machine emulator and virtualizerqemu-tools7.1.0-150500.49.12.1 lock src
Tools for QEMU7.1.0-150500.49.12.1 lock rpm