FlawAtlas
Search the atlas
SUSE-SU-2026:2406-1 Not scored

Security update for qemu

This update for qemu fixes the following issues: - CVE-2023-1544: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554). - CVE-2025-11234: qemu-kvm: use-after-free in websocket handshake code can lead to denial of service (bsc#1250984). - CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a 12-byte information leak when processing specially crafted VMDK files (bsc#1258509).

Exploit probability Not scored
Published June 16, 2026
Required by Not available
Last source change June 17, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS qemu
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 qemu

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2406-1

This update for qemu fixes the following issues: - CVE-2023-1544: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554). - CVE-2025-11234: qemu-kvm: use-after-free in websocket handshake code can lead to denial of service (bsc#1250984). - CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a 12-byte information leak when processing specially crafted VMDK files (bsc#1258509).

View original source

05 / REFERENCES

Further evidence