{"schema_version":"1.7.3","id":"SUSE-SU-2023:3800-1","published":"2023-09-27T11:36:03Z","modified":"2026-02-04T03:39:59.892369Z","related":["CVE-2019-13754","CVE-2021-3750","CVE-2021-3929","CVE-2022-1050","CVE-2022-26354","CVE-2023-0330","CVE-2023-2861","CVE-2023-3180","CVE-2023-3354"],"upstream":["CVE-2019-13754","CVE-2021-3750","CVE-2021-3929","CVE-2022-1050","CVE-2022-26354","CVE-2023-0330","CVE-2023-2861","CVE-2023-3180","CVE-2023-3354"],"summary":"Security update for qemu","details":"This update for qemu fixes the following issues:\n\n- CVE-2022-26354: Fixed a memory leak due to a missing virtqueue detach on error. (bsc#1198712)\n- CVE-2021-3929: Fixed an use-after-free in nvme DMA reentrancy issue. (bsc#1193880)\n- CVE-2023-0330: Fixed a stack overflow due to a DMA reentrancy issue. (bsc#1207205)\n- CVE-2020-13754: Fixed a DoS due to an OOB access during mmio operations. (bsc#1172382)\n- CVE-2023-3354: Fixed a remote unauthenticated DoS due to an improper I/O watch removal in VNC TLS handshake. (bsc#1212850)\n- CVE-2023-3180: Fixed a heap buffer overflow in virtio_crypto_sym_op_helper(). (bsc#1213925)\n- CVE-2023-2861: Fixed improper access control on special files in 9pfs (bsc#1212968).\n- CVE-2022-1050: Fixed use-after-free issue in pvrdma_exec_cmd() (bsc#1197653).\n- CVE-2021-3750: Fixed DMA reentrancy issue leads to use-after-free in hcd-ehci (bsc#1190011).\n\nThe following non-security bug was fixed:\n\n- Prepare for binutils update to 2.41 update (bsc#1215311).\n","affected":[{"package":{"name":"qemu","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.1.1-150100.80.51.5"}]}],"ecosystem_specific":{"binaries":[{"qemu":"3.1.1.1-150100.80.51.5","qemu-arm":"3.1.1.1-150100.80.51.5","qemu-audio-alsa":"3.1.1.1-150100.80.51.5","qemu-audio-oss":"3.1.1.1-150100.80.51.5","qemu-audio-pa":"3.1.1.1-150100.80.51.5","qemu-block-curl":"3.1.1.1-150100.80.51.5","qemu-block-iscsi":"3.1.1.1-150100.80.51.5","qemu-block-rbd":"3.1.1.1-150100.80.51.5","qemu-block-ssh":"3.1.1.1-150100.80.51.5","qemu-guest-agent":"3.1.1.1-150100.80.51.5","qemu-ipxe":"1.0.0+-150100.80.51.5","qemu-kvm":"3.1.1.1-150100.80.51.5","qemu-lang":"3.1.1.1-150100.80.51.5","qemu-seabios":"1.12.0_0_ga698c89-150100.80.51.5","qemu-sgabios":"8-150100.80.51.5","qemu-tools":"3.1.1.1-150100.80.51.5","qemu-ui-curses":"3.1.1.1-150100.80.51.5","qemu-ui-gtk":"3.1.1.1-150100.80.51.5","qemu-vgabios":"1.12.0_0_ga698c89-150100.80.51.5","qemu-x86":"3.1.1.1-150100.80.51.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3800-1.json"}},{"package":{"name":"qemu","ecosystem":"SUSE:Linux Enterprise Server 15 SP1-LTSS","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.1.1-150100.80.51.5"}]}],"ecosystem_specific":{"binaries":[{"qemu":"3.1.1.1-150100.80.51.5","qemu-arm":"3.1.1.1-150100.80.51.5","qemu-audio-alsa":"3.1.1.1-150100.80.51.5","qemu-audio-oss":"3.1.1.1-150100.80.51.5","qemu-audio-pa":"3.1.1.1-150100.80.51.5","qemu-block-curl":"3.1.1.1-150100.80.51.5","qemu-block-iscsi":"3.1.1.1-150100.80.51.5","qemu-block-rbd":"3.1.1.1-150100.80.51.5","qemu-block-ssh":"3.1.1.1-150100.80.51.5","qemu-guest-agent":"3.1.1.1-150100.80.51.5","qemu-ipxe":"1.0.0+-150100.80.51.5","qemu-kvm":"3.1.1.1-150100.80.51.5","qemu-lang":"3.1.1.1-150100.80.51.5","qemu-ppc":"3.1.1.1-150100.80.51.5","qemu-s390":"3.1.1.1-150100.80.51.5","qemu-seabios":"1.12.0_0_ga698c89-150100.80.51.5","qemu-sgabios":"8-150100.80.51.5","qemu-tools":"3.1.1.1-150100.80.51.5","qemu-ui-curses":"3.1.1.1-150100.80.51.5","qemu-ui-gtk":"3.1.1.1-150100.80.51.5","qemu-vgabios":"1.12.0_0_ga698c89-150100.80.51.5","qemu-x86":"3.1.1.1-150100.80.51.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3800-1.json"}},{"package":{"name":"qemu","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP1","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.1.1-150100.80.51.5"}]}],"ecosystem_specific":{"binaries":[{"qemu":"3.1.1.1-150100.80.51.5","qemu-audio-alsa":"3.1.1.1-150100.80.51.5","qemu-audio-oss":"3.1.1.1-150100.80.51.5","qemu-audio-pa":"3.1.1.1-150100.80.51.5","qemu-block-curl":"3.1.1.1-150100.80.51.5","qemu-block-iscsi":"3.1.1.1-150100.80.51.5","qemu-block-rbd":"3.1.1.1-150100.80.51.5","qemu-block-ssh":"3.1.1.1-150100.80.51.5","qemu-guest-agent":"3.1.1.1-150100.80.51.5","qemu-ipxe":"1.0.0+-150100.80.51.5","qemu-kvm":"3.1.1.1-150100.80.51.5","qemu-lang":"3.1.1.1-150100.80.51.5","qemu-ppc":"3.1.1.1-150100.80.51.5","qemu-seabios":"1.12.0_0_ga698c89-150100.80.51.5","qemu-sgabios":"8-150100.80.51.5","qemu-tools":"3.1.1.1-150100.80.51.5","qemu-ui-curses":"3.1.1.1-150100.80.51.5","qemu-ui-gtk":"3.1.1.1-150100.80.51.5","qemu-vgabios":"1.12.0_0_ga698c89-150100.80.51.5","qemu-x86":"3.1.1.1-150100.80.51.5"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3800-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233800-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172382"},{"type":"REPORT","url":"https://bugzilla.suse.com/1190011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1197653"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198712"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212968"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3750"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3929"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-1050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2861"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3180"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3354"}]}