gpp_maybe
Security update for qemu
SUSE-SLE-Module-Server-Applications-15-SP7-2026-39
This update for qemu fixes the following issues: - CVE-2024-6505: qemu-kvm: virtio-net: Fixed queue index out-of-bounds access in software RSS (bsc#1227397) - CVE-2025-12464: net: pad packets to minimum length in qemu_receive_packet() (bsc#1253002) - CVE-2025-11234: qemu-kvm: Fixed use-after-free in websocket handshake code leading to denial of service (bsc#1250984) Other fixes: - Fixed *-virtio-gpu-pci dependency on ARM (bsc#1254286) - block/curl: Fixed curl internal handles handling (bsc#1252768)
-
Release DateJan 6 2026
-
ReferencesBugzilla: 1227397, 1253002, 1254286, 1250984, 1252768
CVEs: CVE-2025-12464, CVE-2024-6505, CVE-2025-11234 -
Typesecurity
-
Severityimportant
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
Server Applications Module 15.7 x86_64
-
Packagesqemu
Machine emulator and virtualizerqemu-sgabios7.1.0-150500.49.36.2 lock src
Serial Graphics Adapter BIOS for QEMU8-150500.49.36.2 lock rpm