<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for qemu</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:1894-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-06-08T13:16:49Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-06-08T13:16:49Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-06-08T13:16:49Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for qemu</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for qemu fixes the following issues:

- Fix OOB access during mmio operations (CVE-2020-13754, bsc#1172382)
- Fix out-of-bounds read information disclosure in icmp6_send_echoreply (CVE-2020-10756, bsc#1172380)
- Fix out-of-bound heap buffer access via an interrupt ID field (CVE-2021-20221, bsc#1181933)
- For the record, these issues are fixed in this package already.
  Most are alternate references to previously mentioned issues:
  (CVE-2019-15890, bsc#1149813, CVE-2020-8608, bsc#1163019,
  CVE-2020-14364, bsc#1175534, CVE-2020-25707, bsc#1178683,
  CVE-2020-25723, bsc#1178935, CVE-2020-29130, bsc#1179477,
  CVE-2021-20257, bsc#1182846, CVE-2021-3419, bsc#1182975,
  bsc#1094725)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">HPE-Helion-OpenStack-8-2021-1894,SUSE-2021-1894,SUSE-OpenStack-Cloud-8-2021-1894,SUSE-OpenStack-Cloud-Crowbar-8-2021-1894,SUSE-SLE-SAP-12-SP3-2021-1894,SUSE-SLE-SERVER-12-SP3-2021-1894,SUSE-SLE-SERVER-12-SP3-BCL-2021-1894</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      <Description>Link for SUSE-SU-2021:1894-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-June/008954.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:1894-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1094725</URL>
      <Description>SUSE Bug 1094725</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1149813</URL>
      <Description>SUSE Bug 1149813</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1163019</URL>
      <Description>SUSE Bug 1163019</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172380</URL>
      <Description>SUSE Bug 1172380</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172382</URL>
      <Description>SUSE Bug 1172382</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1175534</URL>
      <Description>SUSE Bug 1175534</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178683</URL>
      <Description>SUSE Bug 1178683</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178935</URL>
      <Description>SUSE Bug 1178935</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179477</URL>
      <Description>SUSE Bug 1179477</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181933</URL>
      <Description>SUSE Bug 1181933</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182846</URL>
      <Description>SUSE Bug 1182846</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182975</URL>
      <Description>SUSE Bug 1182975</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-15890/</URL>
      <Description>SUSE CVE CVE-2019-15890 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-10756/</URL>
      <Description>SUSE CVE CVE-2020-10756 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13754/</URL>
      <Description>SUSE CVE CVE-2020-13754 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14364/</URL>
      <Description>SUSE CVE CVE-2020-14364 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25707/</URL>
      <Description>SUSE CVE CVE-2020-25707 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25723/</URL>
      <Description>SUSE CVE CVE-2020-25723 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29130/</URL>
      <Description>SUSE CVE CVE-2020-29130 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8608/</URL>
      <Description>SUSE CVE CVE-2020-8608 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20221/</URL>
      <Description>SUSE CVE CVE-2021-20221 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20257/</URL>
      <Description>SUSE CVE CVE-2021-20257 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3419/</URL>
      <Description>SUSE CVE CVE-2021-3419 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="HPE Helion OpenStack 8">
      <Branch Type="Product Name" Name="HPE Helion OpenStack 8">
        <FullProductName ProductID="HPE Helion OpenStack 8" CPE="cpe:/o:suse:hpe-helion-openstack:8">HPE Helion OpenStack 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3-BCL">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP3-BCL">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL" CPE="cpe:/o:suse:sles-bcl:12:sp3">SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP3-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS" CPE="cpe:/o:suse:sles-ltss:12:sp3">SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3" CPE="cpe:/o:suse:sles_sap:12:sp3">SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 8">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 8">
        <FullProductName ProductID="SUSE OpenStack Cloud 8" CPE="cpe:/o:suse:suse-openstack-cloud:8">SUSE OpenStack Cloud 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud Crowbar 8">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud Crowbar 8">
        <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8" CPE="cpe:/o:suse:suse-openstack-cloud-crowbar:8">SUSE OpenStack Cloud Crowbar 8</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="qemu-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-curl-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-iscsi-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-rbd-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-ssh-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-guest-agent-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ipxe-1.0.0+-6.50.1">
      <FullProductName ProductID="qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-kvm-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-lang-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">
      <FullProductName ProductID="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-sgabios-8-6.50.1">
      <FullProductName ProductID="qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-tools-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">
      <FullProductName ProductID="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-x86-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-arm-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-arm-2.9.1-6.50.1">qemu-arm-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-dmg-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-block-dmg-2.9.1-6.50.1">qemu-block-dmg-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-extra-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-extra-2.9.1-6.50.1">qemu-extra-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-linux-user-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-linux-user-2.9.1-6.50.1">qemu-linux-user-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ppc-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-ppc-2.9.1-6.50.1">qemu-ppc-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-s390-2.9.1-6.50.1">
      <FullProductName ProductID="qemu-s390-2.9.1-6.50.1">qemu-s390-2.9.1-6.50.1</FullProductName>
    </Branch>
    <Relationship ProductReference="qemu-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="HPE Helion OpenStack 8">
      <FullProductName ProductID="HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1 as a component of HPE Helion OpenStack 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-BCL">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-BCL</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1">qemu-arm-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1">qemu-ppc-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1">qemu-s390-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server 12 SP3-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1">qemu-ppc-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 8">
      <FullProductName ProductID="SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1">qemu-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1">qemu-block-curl-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1">qemu-block-iscsi-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1">qemu-block-rbd-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1">qemu-block-ssh-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1">qemu-guest-agent-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1">qemu-ipxe-1.0.0+-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1">qemu-kvm-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1">qemu-lang-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1">qemu-sgabios-8-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1">qemu-tools-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1">qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.9.1-6.50.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 8">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1">qemu-x86-2.9.1-6.50.1 as a component of SUSE OpenStack Cloud Crowbar 8</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.</Note>
    </Notes>
    <CVE>CVE-2019-15890</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.8</BaseScoreV3>
        <VectorV3>CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-15890.html</URL>
        <Description>CVE-2019-15890</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149811</URL>
        <Description>SUSE Bug 1149811</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149813</URL>
        <Description>SUSE Bug 1149813</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.</Note>
    </Notes>
    <CVE>CVE-2020-10756</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-10756.html</URL>
        <Description>CVE-2020-10756</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172380</URL>
        <Description>SUSE Bug 1172380</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1184743</URL>
        <Description>SUSE Bug 1184743</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.</Note>
    </Notes>
    <CVE>CVE-2020-13754</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.9</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13754.html</URL>
        <Description>CVE-2020-13754</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172382</URL>
        <Description>SUSE Bug 1172382</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.</Note>
    </Notes>
    <CVE>CVE-2020-14364</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.4</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14364.html</URL>
        <Description>CVE-2020-14364</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175441</URL>
        <Description>SUSE Bug 1175441</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175534</URL>
        <Description>SUSE Bug 1175534</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1176494</URL>
        <Description>SUSE Bug 1176494</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177130</URL>
        <Description>SUSE Bug 1177130</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate is a duplicate of CVE-2020-2891</Note>
    </Notes>
    <CVE>CVE-2020-25707</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>6</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25707.html</URL>
        <Description>CVE-2020-25707</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178683</URL>
        <Description>SUSE Bug 1178683</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179468</URL>
        <Description>SUSE Bug 1179468</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2020-25723</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25723.html</URL>
        <Description>CVE-2020-25723</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178934</URL>
        <Description>SUSE Bug 1178934</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178935</URL>
        <Description>SUSE Bug 1178935</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.</Note>
    </Notes>
    <CVE>CVE-2020-29130</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:S/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>4.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29130.html</URL>
        <Description>CVE-2020-29130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179467</URL>
        <Description>SUSE Bug 1179467</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179477</URL>
        <Description>SUSE Bug 1179477</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.</Note>
    </Notes>
    <CVE>CVE-2020-8608</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8608.html</URL>
        <Description>CVE-2020-8608</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1163018</URL>
        <Description>SUSE Bug 1163018</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1163019</URL>
        <Description>SUSE Bug 1163019</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.</Note>
    </Notes>
    <CVE>CVE-2021-20221</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20221.html</URL>
        <Description>CVE-2021-20221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181933</URL>
        <Description>SUSE Bug 1181933</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20257</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20257.html</URL>
        <Description>CVE-2021-20257</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182577</URL>
        <Description>SUSE Bug 1182577</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182846</URL>
        <Description>SUSE Bug 1182846</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none</Note>
    </Notes>
    <CVE>CVE-2021-3419</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>HPE Helion OpenStack 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>HPE Helion OpenStack 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-BCL:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-arm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-s390-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3-LTSS:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-ppc-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 8:qemu-x86-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-curl-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-iscsi-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-rbd-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-block-ssh-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-guest-agent-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-ipxe-1.0.0+-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-kvm-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-lang-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-seabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-sgabios-8-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-tools-2.9.1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-vgabios-1.10.2_0_g5f4c7b1-6.50.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 8:qemu-x86-2.9.1-6.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211894-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3419.html</URL>
        <Description>CVE-2021-3419</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182968</URL>
        <Description>SUSE Bug 1182968</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182975</URL>
        <Description>SUSE Bug 1182975</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
