{"affected":[{"ecosystem_specific":{"binaries":[{"qemu":"8.2.6-1.1","qemu-accel-tcg-x86":"8.2.6-1.1","qemu-arm":"8.2.6-1.1","qemu-audio-spice":"8.2.6-1.1","qemu-block-curl":"8.2.6-1.1","qemu-block-iscsi":"8.2.6-1.1","qemu-block-rbd":"8.2.6-1.1","qemu-block-ssh":"8.2.6-1.1","qemu-chardev-spice":"8.2.6-1.1","qemu-guest-agent":"8.2.6-1.1","qemu-hw-display-qxl":"8.2.6-1.1","qemu-hw-display-virtio-gpu":"8.2.6-1.1","qemu-hw-display-virtio-gpu-pci":"8.2.6-1.1","qemu-hw-display-virtio-vga":"8.2.6-1.1","qemu-hw-usb-host":"8.2.6-1.1","qemu-hw-usb-redirect":"8.2.6-1.1","qemu-img":"8.2.6-1.1","qemu-ipxe":"8.2.6-1.1","qemu-ksm":"8.2.6-1.1","qemu-lang":"8.2.6-1.1","qemu-pr-helper":"8.2.6-1.1","qemu-s390x":"8.2.6-1.1","qemu-seabios":"8.2.61.16.3_3_ga95067eb-1.1","qemu-tools":"8.2.6-1.1","qemu-ui-opengl":"8.2.6-1.1","qemu-ui-spice-core":"8.2.6-1.1","qemu-vgabios":"8.2.61.16.3_3_ga95067eb-1.1","qemu-x86":"8.2.6-1.1"}]},"package":{"ecosystem":"SUSE:Linux Micro 6.0","name":"qemu","purl":"pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"8.2.6-1.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for qemu fixes the following issues:\n\n- Fix bsc#1221812:\n  * block: Reschedule query-block during qcow2 invalidation (bsc#1221812)\n\n- Fix bsc#1229007, CVE-2024-7409:\n  * nbd/server: CVE-2024-7409: Close stray clients at server-stop (bsc#1229007)\n  * nbd/server: CVE-2024-7409: Drop non-negotiating clients (bsc#1229007)\n  * nbd/server: CVE-2024-7409: Cap default max-connections to 100 (bsc#1229007)\n  * nbd/server: Plumb in new args to nbd_client_add() (bsc#1229007, CVE-2024-7409)\n  * nbd: Minor style and typo fixes (bsc#1229007, CVE-2024-7409)\n\n- Update to version 8.2.6:\n\n  Full backport lists (from the various releases) here:\n   https://lore.kernel.org/qemu-devel/1721203806.547734.831464.nullmailer@tls.msk.ru/\n\n  Some of the upstream backports are:\n   hw/nvme: fix number of PIDs for FDP RUH update\n   sphinx/qapidoc: Fix to generate doc for explicit, unboxed arguments\n   char-stdio: Restore blocking mode of stdout on exit\n   virtio: remove virtio_tswap16s() call in vring_packed_event_read()\n   virtio-pci: Fix the failure process in kvm_virtio_pci_vector_use_one()\n   block: Parse filenames only when explicitly requested\n   iotests/270: Don't store data-file with json: prefix in image\n   iotests/244: Don't store data-file with protocol in image\n   qcow2: Don't open data_file with BDRV_O_NO_IO (bsc#1227322, CVE-2024-4467)\n   target/arm: Fix FJCVTZS vs flush-to-zero\n   target/arm: Fix VCMLA Dd, Dn, Dm[idx]\n   i386/cpu: fixup number of addressable IDs for processor cores in the physical package\n   tests: Update our CI to use CentOS Stream 9 instead of 8\n   migration: Fix file migration with fdset\n   tcg/loongarch64: Fix tcg_out_movi vs some pcrel pointers\n   target/sparc: use signed denominator in sdiv helper\n   linux-user: Make TARGET_NR_setgroups affect only the current thread\n   accel/tcg: Fix typo causing tb->page_addr[1] to not be recorded\n   stdvga: fix screen blanking\n   hw/audio/virtio-snd: Always use little endian audio format\n   ui/gtk: Draw guest frame at refresh cycle\n   virtio-net: drop too short packets early\n   target/i386: fix size of EBP writeback in gen_enter()\n\n","id":"SUSE-SU-2025:20036-1","modified":"2025-02-03T08:53:00Z","published":"2025-02-03T08:53:00Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202520036-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1221812"},{"type":"REPORT","url":"https://bugzilla.suse.com/1227322"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-4467"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-7409"}],"related":["CVE-2024-4467","CVE-2024-7409"],"summary":"Security update for qemu","upstream":["CVE-2024-4467","CVE-2024-7409"]}