{"affected":[{"ecosystem_specific":{"binaries":[{"qemu-img":"9.2.4-150700.3.11.1","qemu-pr-helper":"9.2.4-150700.3.11.1","qemu-tools":"9.2.4-150700.3.11.1","qemu-vmsr-helper":"9.2.4-150700.3.11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","name":"qemu","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.2.4-150700.3.11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"qemu-SLOF":"9.2.4-150700.3.11.1","qemu-accel-qtest":"9.2.4-150700.3.11.1","qemu-arm":"9.2.4-150700.3.11.1","qemu-audio-jack":"9.2.4-150700.3.11.1","qemu-audio-oss":"9.2.4-150700.3.11.1","qemu-block-dmg":"9.2.4-150700.3.11.1","qemu-extra":"9.2.4-150700.3.11.1","qemu-hw-s390x-virtio-gpu-ccw":"9.2.4-150700.3.11.1","qemu-hw-usb-smartcard":"9.2.4-150700.3.11.1","qemu-ivshmem-tools":"9.2.4-150700.3.11.1","qemu-linux-user":"9.2.4-150700.3.11.1","qemu-microvm":"9.2.4-150700.3.11.1","qemu-ppc":"9.2.4-150700.3.11.1","qemu-s390x":"9.2.4-150700.3.11.1","qemu-skiboot":"9.2.4-150700.3.11.1","qemu-vhost-user-gpu":"9.2.4-150700.3.11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","name":"qemu","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.2.4-150700.3.11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"qemu-SLOF":"9.2.4-150700.3.11.1","qemu-accel-qtest":"9.2.4-150700.3.11.1","qemu-arm":"9.2.4-150700.3.11.1","qemu-audio-jack":"9.2.4-150700.3.11.1","qemu-audio-oss":"9.2.4-150700.3.11.1","qemu-block-dmg":"9.2.4-150700.3.11.1","qemu-extra":"9.2.4-150700.3.11.1","qemu-hw-s390x-virtio-gpu-ccw":"9.2.4-150700.3.11.1","qemu-hw-usb-smartcard":"9.2.4-150700.3.11.1","qemu-ivshmem-tools":"9.2.4-150700.3.11.1","qemu-linux-user":"9.2.4-150700.3.11.1","qemu-microvm":"9.2.4-150700.3.11.1","qemu-ppc":"9.2.4-150700.3.11.1","qemu-s390x":"9.2.4-150700.3.11.1","qemu-skiboot":"9.2.4-150700.3.11.1","qemu-vhost-user-gpu":"9.2.4-150700.3.11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","name":"qemu-linux-user","purl":"pkg:rpm/suse/qemu-linux-user&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.2.4-150700.3.11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"qemu":"9.2.4-150700.3.11.1","qemu-SLOF":"9.2.4-150700.3.11.1","qemu-accel-tcg-x86":"9.2.4-150700.3.11.1","qemu-arm":"9.2.4-150700.3.11.1","qemu-audio-alsa":"9.2.4-150700.3.11.1","qemu-audio-dbus":"9.2.4-150700.3.11.1","qemu-audio-pa":"9.2.4-150700.3.11.1","qemu-audio-pipewire":"9.2.4-150700.3.11.1","qemu-audio-spice":"9.2.4-150700.3.11.1","qemu-block-curl":"9.2.4-150700.3.11.1","qemu-block-iscsi":"9.2.4-150700.3.11.1","qemu-block-nfs":"9.2.4-150700.3.11.1","qemu-block-rbd":"9.2.4-150700.3.11.1","qemu-block-ssh":"9.2.4-150700.3.11.1","qemu-chardev-baum":"9.2.4-150700.3.11.1","qemu-chardev-spice":"9.2.4-150700.3.11.1","qemu-guest-agent":"9.2.4-150700.3.11.1","qemu-headless":"9.2.4-150700.3.11.1","qemu-hw-display-qxl":"9.2.4-150700.3.11.1","qemu-hw-display-virtio-gpu":"9.2.4-150700.3.11.1","qemu-hw-display-virtio-gpu-pci":"9.2.4-150700.3.11.1","qemu-hw-display-virtio-vga":"9.2.4-150700.3.11.1","qemu-hw-s390x-virtio-gpu-ccw":"9.2.4-150700.3.11.1","qemu-hw-usb-host":"9.2.4-150700.3.11.1","qemu-hw-usb-redirect":"9.2.4-150700.3.11.1","qemu-ipxe":"9.2.4-150700.3.11.1","qemu-ksm":"9.2.4-150700.3.11.1","qemu-lang":"9.2.4-150700.3.11.1","qemu-ppc":"9.2.4-150700.3.11.1","qemu-s390x":"9.2.4-150700.3.11.1","qemu-seabios":"9.2.41.16.3_3_g3d33c746-150700.3.11.1","qemu-skiboot":"9.2.4-150700.3.11.1","qemu-spice":"9.2.4-150700.3.11.1","qemu-ui-curses":"9.2.4-150700.3.11.1","qemu-ui-dbus":"9.2.4-150700.3.11.1","qemu-ui-gtk":"9.2.4-150700.3.11.1","qemu-ui-opengl":"9.2.4-150700.3.11.1","qemu-ui-spice-app":"9.2.4-150700.3.11.1","qemu-ui-spice-core":"9.2.4-150700.3.11.1","qemu-vgabios":"9.2.41.16.3_3_g3d33c746-150700.3.11.1","qemu-x86":"9.2.4-150700.3.11.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","name":"qemu","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"9.2.4-150700.3.11.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for qemu fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2025-12464: stack-based buffer overflow in the e1000 network device operations can be exploited by a malicious\n  guest user to crash the QEMU process on the host (bsc#1253002).\n- CVE-2025-11234: use-after-free in WebSocket handshake operations can be exploited by a malicious client with network\n  access to the VNC WebSocket port to cause a denial-of-service (bsc#1250984).\n\nOther updates and bugfixes:\n\n- [openSUSE][RPM] spec: require qemu-hw-display-virtio-gpu-pci for x86 too.\n- [openSUSE][RPM] spec: make glusterfs support conditional (bsc#1254494).\n- [openSUSE][RPM]: really fix *-virtio-gpu-pci dependency on ARM (bsc#1254286).\n- block/curl: fix curl internal handles handling (bsc#1252768).\n- [openSUSE][RPM] spec: qemu-vgabios is required on ppc (bsc#1230042).\n","id":"SUSE-SU-2026:0288-1","modified":"2026-01-26T09:04:46Z","published":"2026-01-26T09:04:46Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20260288-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230042"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250984"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252768"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11234"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-12464"}],"related":["CVE-2025-11234","CVE-2025-12464"],"summary":"Security update for qemu","upstream":["CVE-2025-11234","CVE-2025-12464"]}