🛡️ SUSE-SU-2025:20036-1 — qemu (CVE-2024-7409 +1 more)
Description
Security update for qemu
This update for qemu fixes the following issues:
- Fix bsc#1221812:
- block: Reschedule query-block during qcow2 invalidation (bsc#1221812)
- Fix bsc#1229007, CVE-2024-7409:
- nbd/server: CVE-2024-7409: Close stray clients at server-stop (bsc#1229007)
- nbd/server: CVE-2024-7409: Drop non-negotiating clients (bsc#1229007)
- nbd/server: CVE-2024-7409: Cap default max-connections to 100 (bsc#1229007)
- nbd/server: Plumb in new args to nbd_client_add() (bsc#1229007, CVE-2024-7409)
- nbd: Minor style and typo fixes (bsc#1229007, CVE-2024-7409)
- Update to version 8.2.6:
Full backport lists (from the various releases) here:
https://lore.kernel.org/qemu-devel/[email protected]/
Some of the upstream backports are:
hw/nvme: fix number of PIDs for FDP RUH update
sphinx/qapidoc: Fix to generate doc for explicit, unboxed arguments
char-stdio: Restore blocking mode of stdout on exit
virtio: remove virtio_tswap16s() call in vring_packed_event_read()
virtio-pci: Fix the failure process in kvm_virtio_pci_vector_use_one()
block: Parse filenames only when explicitly requested
iotests/270: Don't store data-file with json: prefix in image
iotests/244: Don't store data-file with protocol in image
qcow2: Don't open data_file with BDRV_O_NO_IO (bsc#1227322, CVE-2024-4467)
target/arm: Fix FJCVTZS vs flush-to-zero
target/arm: Fix VCMLA Dd, Dn, Dm[idx]
i386/cpu: fixup number of addressable IDs for processor cores in the physical package
tests: Update our CI to use CentOS Stream 9 instead of 8
migration: Fix file migration with fdset
tcg/loongarch64: Fix tcg_out_movi vs some pcrel pointers
target/sparc: use signed denominator in sdiv helper
linux-user: Make TARGET_NR_setgroups affect only the current thread
accel/tcg: Fix typo causing tb->page_addr[1] to not be recorded
stdvga: fix screen blanking
hw/audio/virtio-snd: Always use little endian audio format
ui/gtk: Draw guest frame at refresh cycle
virtio-net: drop too short packets early
target/i386: fix size of EBP writeback in gen_enter()
Affected software
SUSE-SU-2025:20036-1 is recorded against 1 package.
- qemu (fixed in 8.2.6-1.1)
Timeline and source
Published on 3 February 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| qemu | — | 8.2.6-1.1 |
References
Similar Threats
Free Vulnerability Check
Is your site affected by SUSE-SU-2025:20036-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20036-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.