<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">qemu-7.0.0-53.1 on GA media</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2024:12209</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-06-17T21:45:33Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-06-17T21:45:33Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-06-17T21:45:33Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">qemu-7.0.0-53.1 on GA media</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">These are all security issues fixed in the qemu-7.0.0-53.1 package on the GA media of openSUSE Tumbleweed.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-Tumbleweed-2024-12209</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL/>
      <Description>E-Mail link for openSUSE-SU-2024:12209</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-4206/</URL>
      <Description>SUSE CVE CVE-2021-4206 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-4207/</URL>
      <Description>SUSE CVE CVE-2021-4207 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0216/</URL>
      <Description>SUSE CVE CVE-2022-0216 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-26353/</URL>
      <Description>SUSE CVE CVE-2022-26353 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-26354/</URL>
      <Description>SUSE CVE CVE-2022-26354 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-35414/</URL>
      <Description>SUSE CVE CVE-2022-35414 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Tumbleweed">
      <Branch Type="Product Name" Name="openSUSE Tumbleweed">
        <FullProductName ProductID="openSUSE Tumbleweed" CPE="cpe:/o:opensuse:tumbleweed">openSUSE Tumbleweed</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="qemu-7.0.0-53.1">
      <FullProductName ProductID="qemu-7.0.0-53.1">qemu-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-SLOF-7.0.0-53.1">
      <FullProductName ProductID="qemu-SLOF-7.0.0-53.1">qemu-SLOF-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-accel-qtest-7.0.0-53.1">
      <FullProductName ProductID="qemu-accel-qtest-7.0.0-53.1">qemu-accel-qtest-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-accel-tcg-x86-7.0.0-53.1">
      <FullProductName ProductID="qemu-accel-tcg-x86-7.0.0-53.1">qemu-accel-tcg-x86-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-arm-7.0.0-53.1">
      <FullProductName ProductID="qemu-arm-7.0.0-53.1">qemu-arm-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-alsa-7.0.0-53.1">
      <FullProductName ProductID="qemu-audio-alsa-7.0.0-53.1">qemu-audio-alsa-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-dbus-7.0.0-53.1">
      <FullProductName ProductID="qemu-audio-dbus-7.0.0-53.1">qemu-audio-dbus-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-jack-7.0.0-53.1">
      <FullProductName ProductID="qemu-audio-jack-7.0.0-53.1">qemu-audio-jack-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-oss-7.0.0-53.1">
      <FullProductName ProductID="qemu-audio-oss-7.0.0-53.1">qemu-audio-oss-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-pa-7.0.0-53.1">
      <FullProductName ProductID="qemu-audio-pa-7.0.0-53.1">qemu-audio-pa-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-spice-7.0.0-53.1">
      <FullProductName ProductID="qemu-audio-spice-7.0.0-53.1">qemu-audio-spice-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-curl-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-curl-7.0.0-53.1">qemu-block-curl-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-dmg-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-dmg-7.0.0-53.1">qemu-block-dmg-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-gluster-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-gluster-7.0.0-53.1">qemu-block-gluster-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-iscsi-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-iscsi-7.0.0-53.1">qemu-block-iscsi-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-nfs-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-nfs-7.0.0-53.1">qemu-block-nfs-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-rbd-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-rbd-7.0.0-53.1">qemu-block-rbd-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-ssh-7.0.0-53.1">
      <FullProductName ProductID="qemu-block-ssh-7.0.0-53.1">qemu-block-ssh-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-chardev-baum-7.0.0-53.1">
      <FullProductName ProductID="qemu-chardev-baum-7.0.0-53.1">qemu-chardev-baum-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-chardev-spice-7.0.0-53.1">
      <FullProductName ProductID="qemu-chardev-spice-7.0.0-53.1">qemu-chardev-spice-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-extra-7.0.0-53.1">
      <FullProductName ProductID="qemu-extra-7.0.0-53.1">qemu-extra-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-guest-agent-7.0.0-53.1">
      <FullProductName ProductID="qemu-guest-agent-7.0.0-53.1">qemu-guest-agent-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-display-qxl-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-display-qxl-7.0.0-53.1">qemu-hw-display-qxl-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-display-virtio-gpu-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-display-virtio-gpu-7.0.0-53.1">qemu-hw-display-virtio-gpu-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-display-virtio-gpu-pci-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-display-virtio-gpu-pci-7.0.0-53.1">qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-display-virtio-vga-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-display-virtio-vga-7.0.0-53.1">qemu-hw-display-virtio-vga-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1">qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-usb-host-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-usb-host-7.0.0-53.1">qemu-hw-usb-host-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-usb-redirect-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-usb-redirect-7.0.0-53.1">qemu-hw-usb-redirect-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-hw-usb-smartcard-7.0.0-53.1">
      <FullProductName ProductID="qemu-hw-usb-smartcard-7.0.0-53.1">qemu-hw-usb-smartcard-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ipxe-1.0.0+-53.1">
      <FullProductName ProductID="qemu-ipxe-1.0.0+-53.1">qemu-ipxe-1.0.0+-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ivshmem-tools-7.0.0-53.1">
      <FullProductName ProductID="qemu-ivshmem-tools-7.0.0-53.1">qemu-ivshmem-tools-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ksm-7.0.0-53.1">
      <FullProductName ProductID="qemu-ksm-7.0.0-53.1">qemu-ksm-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-kvm-7.0.0-53.1">
      <FullProductName ProductID="qemu-kvm-7.0.0-53.1">qemu-kvm-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-lang-7.0.0-53.1">
      <FullProductName ProductID="qemu-lang-7.0.0-53.1">qemu-lang-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-microvm-7.0.0-53.1">
      <FullProductName ProductID="qemu-microvm-7.0.0-53.1">qemu-microvm-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ppc-7.0.0-53.1">
      <FullProductName ProductID="qemu-ppc-7.0.0-53.1">qemu-ppc-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-s390x-7.0.0-53.1">
      <FullProductName ProductID="qemu-s390x-7.0.0-53.1">qemu-s390x-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-seabios-1.16.0_0_gd239552-53.1">
      <FullProductName ProductID="qemu-seabios-1.16.0_0_gd239552-53.1">qemu-seabios-1.16.0_0_gd239552-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-sgabios-8-53.1">
      <FullProductName ProductID="qemu-sgabios-8-53.1">qemu-sgabios-8-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-skiboot-7.0.0-53.1">
      <FullProductName ProductID="qemu-skiboot-7.0.0-53.1">qemu-skiboot-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-tools-7.0.0-53.1">
      <FullProductName ProductID="qemu-tools-7.0.0-53.1">qemu-tools-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-curses-7.0.0-53.1">
      <FullProductName ProductID="qemu-ui-curses-7.0.0-53.1">qemu-ui-curses-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-dbus-7.0.0-53.1">
      <FullProductName ProductID="qemu-ui-dbus-7.0.0-53.1">qemu-ui-dbus-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-gtk-7.0.0-53.1">
      <FullProductName ProductID="qemu-ui-gtk-7.0.0-53.1">qemu-ui-gtk-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-opengl-7.0.0-53.1">
      <FullProductName ProductID="qemu-ui-opengl-7.0.0-53.1">qemu-ui-opengl-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-spice-app-7.0.0-53.1">
      <FullProductName ProductID="qemu-ui-spice-app-7.0.0-53.1">qemu-ui-spice-app-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-spice-core-7.0.0-53.1">
      <FullProductName ProductID="qemu-ui-spice-core-7.0.0-53.1">qemu-ui-spice-core-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vgabios-1.16.0_0_gd239552-53.1">
      <FullProductName ProductID="qemu-vgabios-1.16.0_0_gd239552-53.1">qemu-vgabios-1.16.0_0_gd239552-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vhost-user-gpu-7.0.0-53.1">
      <FullProductName ProductID="qemu-vhost-user-gpu-7.0.0-53.1">qemu-vhost-user-gpu-7.0.0-53.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-x86-7.0.0-53.1">
      <FullProductName ProductID="qemu-x86-7.0.0-53.1">qemu-x86-7.0.0-53.1</FullProductName>
    </Branch>
    <Relationship ProductReference="qemu-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-7.0.0-53.1">qemu-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-SLOF-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1">qemu-SLOF-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-accel-qtest-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1">qemu-accel-qtest-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-accel-tcg-x86-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1">qemu-accel-tcg-x86-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-arm-7.0.0-53.1">qemu-arm-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1">qemu-audio-alsa-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-dbus-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1">qemu-audio-dbus-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-jack-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1">qemu-audio-jack-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-oss-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1">qemu-audio-oss-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1">qemu-audio-pa-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-spice-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1">qemu-audio-spice-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1">qemu-block-curl-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-dmg-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1">qemu-block-dmg-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-gluster-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1">qemu-block-gluster-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1">qemu-block-iscsi-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-nfs-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1">qemu-block-nfs-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1">qemu-block-rbd-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1">qemu-block-ssh-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-chardev-baum-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1">qemu-chardev-baum-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-chardev-spice-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1">qemu-chardev-spice-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-extra-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-extra-7.0.0-53.1">qemu-extra-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1">qemu-guest-agent-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-display-qxl-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1">qemu-hw-display-qxl-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-display-virtio-gpu-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1">qemu-hw-display-virtio-gpu-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-display-virtio-gpu-pci-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1">qemu-hw-display-virtio-gpu-pci-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-display-virtio-vga-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1">qemu-hw-display-virtio-vga-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1">qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-usb-host-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1">qemu-hw-usb-host-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-usb-redirect-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1">qemu-hw-usb-redirect-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-hw-usb-smartcard-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1">qemu-hw-usb-smartcard-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1">qemu-ipxe-1.0.0+-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ivshmem-tools-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1">qemu-ivshmem-tools-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ksm-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1">qemu-ksm-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1">qemu-kvm-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-lang-7.0.0-53.1">qemu-lang-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-microvm-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1">qemu-microvm-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1">qemu-ppc-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390x-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1">qemu-s390x-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.16.0_0_gd239552-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1">qemu-seabios-1.16.0_0_gd239552-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-sgabios-8-53.1">qemu-sgabios-8-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-skiboot-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1">qemu-skiboot-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-tools-7.0.0-53.1">qemu-tools-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1">qemu-ui-curses-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-dbus-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1">qemu-ui-dbus-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1">qemu-ui-gtk-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-opengl-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1">qemu-ui-opengl-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-spice-app-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1">qemu-ui-spice-app-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-spice-core-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1">qemu-ui-spice-core-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.16.0_0_gd239552-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1">qemu-vgabios-1.16.0_0_gd239552-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vhost-user-gpu-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1">qemu-vhost-user-gpu-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-7.0.0-53.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Tumbleweed">
      <FullProductName ProductID="openSUSE Tumbleweed:qemu-x86-7.0.0-53.1">qemu-x86-7.0.0-53.1 as a component of openSUSE Tumbleweed</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.</Note>
    </Notes>
    <CVE>CVE-2021-4206</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:qemu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-arm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-extra-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-lang-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-sgabios-8-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-x86-7.0.0-53.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-4206.html</URL>
        <Description>CVE-2021-4206</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198035</URL>
        <Description>SUSE Bug 1198035</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211582</URL>
        <Description>SUSE Bug 1211582</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor-&gt;header.width` and `cursor-&gt;header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.</Note>
    </Notes>
    <CVE>CVE-2021-4207</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:qemu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-arm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-extra-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-lang-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-sgabios-8-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-x86-7.0.0-53.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-4207.html</URL>
        <Description>CVE-2021-4207</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198037</URL>
        <Description>SUSE Bug 1198037</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2022-0216</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:qemu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-arm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-extra-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-lang-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-sgabios-8-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-x86-7.0.0-53.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0216.html</URL>
        <Description>CVE-2022-0216</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198038</URL>
        <Description>SUSE Bug 1198038</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748, which forgot to unmap the cached virtqueue elements on error, leading to memory leakage and other unexpected results. Affected QEMU version: 6.2.0.</Note>
    </Notes>
    <CVE>CVE-2022-26353</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:qemu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-arm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-extra-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-lang-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-sgabios-8-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-x86-7.0.0-53.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-26353.html</URL>
        <Description>CVE-2022-26353</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198711</URL>
        <Description>SUSE Bug 1198711</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions &lt;= 6.2.0.</Note>
    </Notes>
    <CVE>CVE-2022-26354</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:qemu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-arm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-extra-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-lang-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-sgabios-8-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-x86-7.0.0-53.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-26354.html</URL>
        <Description>CVE-2022-26354</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198712</URL>
        <Description>SUSE Bug 1198712</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** DISPUTED ** softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE: a third party states that the Non-virtualization Use Case in the qemu.org reference applies here, i.e., "Bugs affecting the non-virtualization use case are not considered security bugs at this time."</Note>
    </Notes>
    <CVE>CVE-2022-35414</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Tumbleweed:qemu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-SLOF-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-qtest-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-accel-tcg-x86-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-arm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-alsa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-jack-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-oss-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-pa-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-audio-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-curl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-dmg-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-gluster-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-iscsi-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-nfs-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-rbd-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-block-ssh-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-baum-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-chardev-spice-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-extra-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-guest-agent-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-qxl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-gpu-pci-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-display-virtio-vga-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-s390x-virtio-gpu-ccw-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-host-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-redirect-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-hw-usb-smartcard-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ipxe-1.0.0+-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ivshmem-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ksm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-kvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-lang-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-microvm-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ppc-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-s390x-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-seabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-sgabios-8-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-skiboot-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-tools-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-curses-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-dbus-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-gtk-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-opengl-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-app-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-ui-spice-core-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vgabios-1.16.0_0_gd239552-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-vhost-user-gpu-7.0.0-53.1</ProductID>
        <ProductID>openSUSE Tumbleweed:qemu-x86-7.0.0-53.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL/>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-35414.html</URL>
        <Description>CVE-2022-35414</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201367</URL>
        <Description>SUSE Bug 1201367</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
