Security update for qemu
This update for qemu fixes the following issues: - CVE-2023-1544: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554). - CVE-2025-11234: qemu-kvm: use-after-free in websocket handshake code can lead to denial of service (bsc#1250984). - CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a 12-byte information leak when processing specially crafted VMDK files (bsc#1258509).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for qemu fixes the following issues: - CVE-2023-1544: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554). - CVE-2025-11234: qemu-kvm: use-after-free in websocket handshake code can lead to denial of service (bsc#1250984). - CVE-2026-2243: incorrect bounds check leads to heap out-of-bounds read and a 12-byte information leak when processing specially crafted VMDK files (bsc#1258509).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1209554
- https://bugzilla.suse.com/1250984
- https://bugzilla.suse.com/1258509
- https://www.suse.com/security/cve/CVE-2023-1544
- https://www.suse.com/security/cve/CVE-2025-11234
- https://www.suse.com/security/cve/CVE-2026-2243
- https://www.suse.com/support/update/announcement/2026/suse-su-20262406-1/