Security update for qemu
This update for qemu fixes the following issues: - CVE-2021-3750: Fixed DMA reentrancy issue that could lead to use-after-free (bsc#1190011) - CVE-2022-0216: Fixed use-after-free in lsi_do_msgout function in hw/scsi/lsi53c895a.c (bsc#1198038) - CVE-2023-0330: Fixed DMA reentrancy issue that could lead to stack overflow (bsc#1207205) - CVE-2023-3180: Fixed heap buffer overflow in virtio_crypto_sym_op_helper() (bsc#1213925) - CVE-2023-3354: Fixed improper I/O watch removal in VNC TLS handshake that could lead to remote unauthenticated denial of service (bsc#1212850)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for qemu fixes the following issues: - CVE-2021-3750: Fixed DMA reentrancy issue that could lead to use-after-free (bsc#1190011) - CVE-2022-0216: Fixed use-after-free in lsi_do_msgout function in hw/scsi/lsi53c895a.c (bsc#1198038) - CVE-2023-0330: Fixed DMA reentrancy issue that could lead to stack overflow (bsc#1207205) - CVE-2023-3180: Fixed heap buffer overflow in virtio_crypto_sym_op_helper() (bsc#1213925) - CVE-2023-3354: Fixed improper I/O watch removal in VNC TLS handshake that could lead to remote unauthenticated denial of service (bsc#1212850)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1190011
- https://bugzilla.suse.com/1198038
- https://bugzilla.suse.com/1207205
- https://bugzilla.suse.com/1212850
- https://bugzilla.suse.com/1213925
- https://www.suse.com/security/cve/CVE-2021-3750
- https://www.suse.com/security/cve/CVE-2022-0216
- https://www.suse.com/security/cve/CVE-2023-0330
- https://www.suse.com/security/cve/CVE-2023-3180
- https://www.suse.com/security/cve/CVE-2023-3354
- https://www.suse.com/support/update/announcement/2024/suse-su-20241395-1/