Skip to content
openSUSE: QEMU Important Buffer Overflow Crashes SUSE-SU-2026:0043

openSUSE: QEMU Important Buffer Overflow Crashes SUSE-SU-2026:0043

Linuxsecurity LinuxSecurity Advisories January 7, 2026

This update for qemu fixes the following issues: Security issues fixed: * CVE-2023-1544: out-of-bounds read in VMWare's paravirtual RDMA device operations can be exploited through a malicious guest driver to crash the QEMU process on the host (bsc#1209554). * CVE-2024-6505: heap-based buffer overflow in the virtio-net device operations can be exploited by a malicious privileged user to crash the QEMU process on the host (bsc#1227397). * CVE-2025-12464: stack-based buffer overflow in the e1000 network device operations can be exploited by a malicious guest user to crash the QEMU process on the host (bsc#1253002). Other updates and bugfixes: * [openSUSE][RPM] spec: require qemu-hw-display-virtio-gpu-pci for x86 too. * [openSUSE][RPM} spec: delete old specfile constructs. * block/curl: fix curl internal handles handling (bsc#1252768). * [openSUSE][RPM]: really fix *-virtio-gpu-pci dependency on ARM (bsc#1254286).

## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-43=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2026-43=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2026-43=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2026-43=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-43=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-43=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-43=1 * SUSE Linux Enterprise Micro for Rancher 5.4 Read the Full Advisory

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-43=1

* SUSE Manager Proxy 4.3 LTS

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2026-43=1

* SUSE Manager Retail Branch Server 4.3 LTS

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-

Server-4.3-LTS-2026-43=1

* SUSE Manager Server 4.3 LTS

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2026-43=1

zypper in -t patch SUSE-2026-43=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2026-43=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2026-43=1

* SUSE Linux Enterprise Micro for Rancher 5.4

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * qemu-block-curl-6.2.0-150400.37.46.1 * qemu-hw-usb-host-debuginfo-6.2.0-150400.37.46.1 * qemu-ui-opengl-debuginfo-6.2.0-150400.37.46.1 * qemu-hw-usb-host-6.2.0-150400.37.46.1 * qemu-hw-usb-redirect-6.2.0-150400.37.46.1 * qemu-hw-display-virtio-vga-debuginfo-6.2.0-150400.37.46.1 * qemu-block-iscsi-debuginfo-6.2.0-150400.37.46.1 * qemu-guest-agent-debuginfo-6.2.0-150400.37.46.1 * qemu-6.2.0-150400.37.46.1 * qemu-ui-curses-6.2.0-150400.37.46.1 * qemu-lang-6.2.0-150400.37.46.1 * qemu-debuginfo-6.2.0-150400.37.46.1 * qemu-hw-display-qxl-6.2.0-150400.37.46.1 * qemu-debugsource-6.2.0-150400.37.46.1 * qemu-block-rbd-6.2.0-150400.37.46.1 * qemu-hw-display-virtio-vga-6.2.0-150400.37.46.1 * qemu-tools-6.2.0-150400.37.46.1 * qemu-block-ssh-debuginfo-6.2.0-150400.37.46.1 * qemu-ui-gtk-6.2.0-150400.37.46.1 * Read the Full Advisory

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)

* qemu-block-curl-6.2.0-150400.37.46.1

* qemu-hw-usb-host-debuginfo-6.2.0-150400.37.46.1

* qemu-ui-opengl-debuginfo-6.2.0-150400.37.46.1

* qemu-hw-usb-host-6.2.0-150400.37.46.1

* qemu-hw-usb-redirect-6.2.0-150400.37.46.1

* qemu-hw-display-virtio-vga-debuginfo-6.2.0-150400.37.46.1

* qemu-block-iscsi-debuginfo-6.2.0-150400.37.46.1

* qemu-guest-agent-debuginfo-6.2.0-150400.37.46.1

* qemu-6.2.0-150400.37.46.1

* qemu-ui-curses-6.2.0-150400.37.46.1

* qemu-lang-6.2.0-150400.37.46.1

* qemu-debuginfo-6.2.0-150400.37.46.1

* qemu-hw-display-qxl-6.2.0-150400.37.46.1

* qemu-debugsource-6.2.0-150400.37.46.1

* qemu-block-rbd-6.2.0-150400.37.46.1

* qemu-hw-display-virtio-vga-6.2.0-150400.37.46.1

* qemu-tools-6.2.0-150400.37.46.1

* qemu-block-ssh-debuginfo-6.2.0-150400.37.46.1

* qemu-ui-gtk-6.2.0-150400.37.46.1

* bsc#1209554 * bsc#1227397 * bsc#1252768 * bsc#1253002 * bsc#1254286 ## References: * * * * * * * *

*

*

*

*

*

*

*

*

Extracted Entities