Security update for qemu
This update for qemu fixes the following issues: - CVE-2022-4144: Fixed unsafe address translation can lead to out-of-bounds read in qxl_phys2virt (bsc#1205808). - CVE-2021-3507: Fixed heap buffer overflow in DMA read data transfers in fdc (bsc#1185000). The following non-security bugs were fixed: - Fix bsc#1202364. - Introduce max_hw_iov for use in scsi-generic (bsc#1190425)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for qemu fixes the following issues: - CVE-2022-4144: Fixed unsafe address translation can lead to out-of-bounds read in qxl_phys2virt (bsc#1205808). - CVE-2021-3507: Fixed heap buffer overflow in DMA read data transfers in fdc (bsc#1185000). The following non-security bugs were fixed: - Fix bsc#1202364. - Introduce max_hw_iov for use in scsi-generic (bsc#1190425)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1185000
- https://bugzilla.suse.com/1190425
- https://bugzilla.suse.com/1202364
- https://bugzilla.suse.com/1205808
- https://www.suse.com/security/cve/CVE-2021-3507
- https://www.suse.com/security/cve/CVE-2022-4144
- https://www.suse.com/support/update/announcement/2023/suse-su-20230878-1/