FlawAtlas
Search the atlas
SUSE-SU-2024:1395-1 Not scored

Security update for qemu

This update for qemu fixes the following issues: - CVE-2021-3750: Fixed DMA reentrancy issue that could lead to use-after-free (bsc#1190011) - CVE-2022-0216: Fixed use-after-free in lsi_do_msgout function in hw/scsi/lsi53c895a.c (bsc#1198038) - CVE-2023-0330: Fixed DMA reentrancy issue that could lead to stack overflow (bsc#1207205) - CVE-2023-3180: Fixed heap buffer overflow in virtio_crypto_sym_op_helper() (bsc#1213925) - CVE-2023-3354: Fixed improper I/O watch removal in VNC TLS handshake that could lead to remote unauthenticated denial of service (bsc#1212850)

Exploit probability Not scored
Published April 23, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5 qemu
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 qemu

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:1395-1

This update for qemu fixes the following issues: - CVE-2021-3750: Fixed DMA reentrancy issue that could lead to use-after-free (bsc#1190011) - CVE-2022-0216: Fixed use-after-free in lsi_do_msgout function in hw/scsi/lsi53c895a.c (bsc#1198038) - CVE-2023-0330: Fixed DMA reentrancy issue that could lead to stack overflow (bsc#1207205) - CVE-2023-3180: Fixed heap buffer overflow in virtio_crypto_sym_op_helper() (bsc#1213925) - CVE-2023-3354: Fixed improper I/O watch removal in VNC TLS handshake that could lead to remote unauthenticated denial of service (bsc#1212850)

View original source

05 / REFERENCES

Further evidence