SUSE-SU-2024:1103-1

Advisory lineage Upstream: 5 Downstream: 0
Published: 03 Apr 2024, 12:11
Last modified:04 Feb 2026, 04:40

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Apr 2024, 12:11
Published
Vulnerability first disclosed
04 Feb 2026, 04:40
Last Modified
Vulnerability information updated

Description

Security update for qemu This update for qemu fixes the following issues: - CVE-2024-26327: Fixed buffer overflow via invalid SR/IOV NumVFs value (bsc#1220062). - CVE-2024-24474: Fixed integer overflow results in buffer overflow via SCSI command (bsc#1220134). - CVE-2023-6693: Fixed stack buffer overflow in virtio_net_flush_tx() (bsc#1218484). - CVE-2023-1544: Fixed out-of-bounds read in pvrdma_ring_next_elem_read() (bsc#1209554). - CVE-2024-26328: Fixed invalid NumVFs value handled in NVME SR/IOV implementation (bsc#1220065). The following non-security bug was fixed: - Removing in-use mediated device should fail with error message instead of hang (bsc#1205316).

Affected Systems

  • opensuseqemu&distro=openSUSE Leap 15.5

    < 7.1.0-150500.49.12.1

  • suseqemu&distro=SUSE Linux Enterprise Micro 5.5

    < 7.1.0-150500.49.12.1

  • suseqemu&distro=SUSE Linux Enterprise Module for Basesystem 15 SP5

    < 7.1.0-150500.49.12.1

  • suseqemu&distro=SUSE Linux Enterprise Module for Package Hub 15 SP5

    < 7.1.0-150500.49.12.1

  • suseqemu&distro=SUSE Linux Enterprise Module for Server Applications 15 SP5

    < 7.1.0-150500.49.12.1

References (12)