{"schema_version":"1.7.3","id":"SUSE-SU-2023:3721-1","published":"2023-09-21T07:57:13Z","modified":"2026-02-04T04:33:33.102505Z","related":["CVE-2020-13754","CVE-2021-3638","CVE-2021-3750","CVE-2021-3929","CVE-2022-1050","CVE-2022-26354","CVE-2023-0330","CVE-2023-2861","CVE-2023-3180","CVE-2023-3354"],"upstream":["CVE-2020-13754","CVE-2021-3638","CVE-2021-3750","CVE-2021-3929","CVE-2022-1050","CVE-2022-26354","CVE-2023-0330","CVE-2023-2861","CVE-2023-3180","CVE-2023-3354"],"summary":"Security update for qemu","details":"This update for qemu fixes the following issues:\n\n- CVE-2022-26354: Fixed a memory leak due to a missing virtqueue detach on error. (bsc#1198712)\n- CVE-2021-3929: Fixed an use-after-free in nvme DMA reentrancy issue. (bsc#1193880)\n- CVE-2023-0330: Fixed a stack overflow due to a DMA reentrancy issue. (bsc#1207205)\n- CVE-2020-13754: Fixed a DoS due to an OOB access during mmio operations. (bsc#1172382)\n- CVE-2023-3354: Fixed a remote unauthenticated DoS due to an improper I/O watch removal in VNC TLS handshake. (bsc#1212850)\n- CVE-2023-3180: Fixed a heap buffer overflow in virtio_crypto_sym_op_helper(). (bsc#1213925)\n- CVE-2021-3638: Fixed an out-of-bounds write due to an inconsistent check in ati_2d_blt(). (bsc#1188609)\n- CVE-2021-3750: Fixed an use-after-free in DMA reentrancy issue. (bsc#1190011)\n- CVE-2023-2861: Fixed improper access control on special files in 9pfs (bsc#1212968).\n- CVE-2022-1050: Fixed use-after-free issue in pvrdma_exec_cmd() (bsc#1197653).\n\nThe following non-security bug was fixed:\n\n- Prepare for binutils update to 2.41 update (bsc#1215311).\n","affected":[{"package":{"name":"qemu","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.1-150200.79.1"}]}],"ecosystem_specific":{"binaries":[{"qemu":"4.2.1-150200.79.1","qemu-arm":"4.2.1-150200.79.1","qemu-audio-alsa":"4.2.1-150200.79.1","qemu-audio-pa":"4.2.1-150200.79.1","qemu-block-curl":"4.2.1-150200.79.1","qemu-block-iscsi":"4.2.1-150200.79.1","qemu-block-rbd":"4.2.1-150200.79.1","qemu-block-ssh":"4.2.1-150200.79.1","qemu-guest-agent":"4.2.1-150200.79.1","qemu-ipxe":"1.0.0+-150200.79.1","qemu-kvm":"4.2.1-150200.79.1","qemu-lang":"4.2.1-150200.79.1","qemu-microvm":"4.2.1-150200.79.1","qemu-seabios":"1.12.1+-150200.79.1","qemu-sgabios":"8-150200.79.1","qemu-tools":"4.2.1-150200.79.1","qemu-ui-curses":"4.2.1-150200.79.1","qemu-ui-gtk":"4.2.1-150200.79.1","qemu-ui-spice-app":"4.2.1-150200.79.1","qemu-vgabios":"1.12.1+-150200.79.1","qemu-x86":"4.2.1-150200.79.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3721-1.json"}},{"package":{"name":"qemu","ecosystem":"SUSE:Linux Enterprise Server 15 SP2-LTSS","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.1-150200.79.1"}]}],"ecosystem_specific":{"binaries":[{"qemu":"4.2.1-150200.79.1","qemu-arm":"4.2.1-150200.79.1","qemu-audio-alsa":"4.2.1-150200.79.1","qemu-audio-pa":"4.2.1-150200.79.1","qemu-block-curl":"4.2.1-150200.79.1","qemu-block-iscsi":"4.2.1-150200.79.1","qemu-block-rbd":"4.2.1-150200.79.1","qemu-block-ssh":"4.2.1-150200.79.1","qemu-guest-agent":"4.2.1-150200.79.1","qemu-ipxe":"1.0.0+-150200.79.1","qemu-kvm":"4.2.1-150200.79.1","qemu-lang":"4.2.1-150200.79.1","qemu-microvm":"4.2.1-150200.79.1","qemu-ppc":"4.2.1-150200.79.1","qemu-s390":"4.2.1-150200.79.1","qemu-seabios":"1.12.1+-150200.79.1","qemu-sgabios":"8-150200.79.1","qemu-tools":"4.2.1-150200.79.1","qemu-ui-curses":"4.2.1-150200.79.1","qemu-ui-gtk":"4.2.1-150200.79.1","qemu-ui-spice-app":"4.2.1-150200.79.1","qemu-vgabios":"1.12.1+-150200.79.1","qemu-x86":"4.2.1-150200.79.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3721-1.json"}},{"package":{"name":"qemu","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP2","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.1-150200.79.1"}]}],"ecosystem_specific":{"binaries":[{"qemu":"4.2.1-150200.79.1","qemu-audio-alsa":"4.2.1-150200.79.1","qemu-audio-pa":"4.2.1-150200.79.1","qemu-block-curl":"4.2.1-150200.79.1","qemu-block-iscsi":"4.2.1-150200.79.1","qemu-block-rbd":"4.2.1-150200.79.1","qemu-block-ssh":"4.2.1-150200.79.1","qemu-guest-agent":"4.2.1-150200.79.1","qemu-ipxe":"1.0.0+-150200.79.1","qemu-kvm":"4.2.1-150200.79.1","qemu-lang":"4.2.1-150200.79.1","qemu-microvm":"4.2.1-150200.79.1","qemu-ppc":"4.2.1-150200.79.1","qemu-seabios":"1.12.1+-150200.79.1","qemu-sgabios":"8-150200.79.1","qemu-tools":"4.2.1-150200.79.1","qemu-ui-curses":"4.2.1-150200.79.1","qemu-ui-gtk":"4.2.1-150200.79.1","qemu-ui-spice-app":"4.2.1-150200.79.1","qemu-vgabios":"1.12.1+-150200.79.1","qemu-x86":"4.2.1-150200.79.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3721-1.json"}},{"package":{"name":"qemu","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/qemu&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.1-150200.79.1"}]}],"ecosystem_specific":{"binaries":[{"qemu-s390":"4.2.1-150200.79.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3721-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172382"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1190011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1197653"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198712"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212968"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-13754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3638"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3750"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3929"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3180"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3354"}]}