<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for qemu</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2023:3721-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2023-09-21T07:57:13Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2023-09-21T07:57:13Z</InitialReleaseDate>
    <CurrentReleaseDate>2023-09-21T07:57:13Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for qemu</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for qemu fixes the following issues:

- CVE-2022-26354: Fixed a memory leak due to a missing virtqueue detach on error. (bsc#1198712)
- CVE-2021-3929: Fixed an use-after-free in nvme DMA reentrancy issue. (bsc#1193880)
- CVE-2023-0330: Fixed a stack overflow due to a DMA reentrancy issue. (bsc#1207205)
- CVE-2020-13754: Fixed a DoS due to an OOB access during mmio operations. (bsc#1172382)
- CVE-2023-3354: Fixed a remote unauthenticated DoS due to an improper I/O watch removal in VNC TLS handshake. (bsc#1212850)
- CVE-2023-3180: Fixed a heap buffer overflow in virtio_crypto_sym_op_helper(). (bsc#1213925)
- CVE-2021-3638: Fixed an out-of-bounds write due to an inconsistent check in ati_2d_blt(). (bsc#1188609)
- CVE-2021-3750: Fixed an use-after-free in DMA reentrancy issue. (bsc#1190011)
- CVE-2023-2861: Fixed improper access control on special files in 9pfs (bsc#1212968).
- CVE-2022-1050: Fixed use-after-free issue in pvrdma_exec_cmd() (bsc#1197653).

The following non-security bug was fixed:

- Prepare for binutils update to 2.41 update (bsc#1215311).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2023-3721,SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-3721,SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-3721,SUSE-SLE-Product-SLES_SAP-15-SP2-2023-3721,openSUSE-SLE-15.4-2023-3721</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      <Description>Link for SUSE-SU-2023:3721-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2023-September/016281.html</URL>
      <Description>E-Mail link for SUSE-SU-2023:3721-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172382</URL>
      <Description>SUSE Bug 1172382</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1188609</URL>
      <Description>SUSE Bug 1188609</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1190011</URL>
      <Description>SUSE Bug 1190011</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1193880</URL>
      <Description>SUSE Bug 1193880</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1197653</URL>
      <Description>SUSE Bug 1197653</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1198712</URL>
      <Description>SUSE Bug 1198712</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1207205</URL>
      <Description>SUSE Bug 1207205</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1212850</URL>
      <Description>SUSE Bug 1212850</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1212968</URL>
      <Description>SUSE Bug 1212968</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1213925</URL>
      <Description>SUSE Bug 1213925</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1215311</URL>
      <Description>SUSE Bug 1215311</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13754/</URL>
      <Description>SUSE CVE CVE-2020-13754 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3638/</URL>
      <Description>SUSE CVE CVE-2021-3638 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3750/</URL>
      <Description>SUSE CVE CVE-2021-3750 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3929/</URL>
      <Description>SUSE CVE CVE-2021-3929 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-1050/</URL>
      <Description>SUSE CVE CVE-2022-1050 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-26354/</URL>
      <Description>SUSE CVE CVE-2022-26354 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-0330/</URL>
      <Description>SUSE CVE CVE-2023-0330 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-2861/</URL>
      <Description>SUSE CVE CVE-2023-2861 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-3180/</URL>
      <Description>SUSE CVE CVE-2023-3180 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-3354/</URL>
      <Description>SUSE CVE CVE-2023-3354 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp2">SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp2">SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2" CPE="cpe:/o:suse:sles_sap:15:sp2">SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.4">
      <Branch Type="Product Name" Name="openSUSE Leap 15.4">
        <FullProductName ProductID="openSUSE Leap 15.4" CPE="cpe:/o:opensuse:leap:15.4">openSUSE Leap 15.4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="qemu-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-4.2.1-150200.79.1">qemu-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-arm-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-arm-4.2.1-150200.79.1">qemu-arm-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-alsa-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-audio-alsa-4.2.1-150200.79.1">qemu-audio-alsa-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-pa-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-audio-pa-4.2.1-150200.79.1">qemu-audio-pa-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-curl-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-block-curl-4.2.1-150200.79.1">qemu-block-curl-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-dmg-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-block-dmg-4.2.1-150200.79.1">qemu-block-dmg-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-iscsi-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-block-iscsi-4.2.1-150200.79.1">qemu-block-iscsi-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-rbd-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-block-rbd-4.2.1-150200.79.1">qemu-block-rbd-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-ssh-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-block-ssh-4.2.1-150200.79.1">qemu-block-ssh-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-extra-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-extra-4.2.1-150200.79.1">qemu-extra-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-guest-agent-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-guest-agent-4.2.1-150200.79.1">qemu-guest-agent-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ipxe-1.0.0+-150200.79.1">
      <FullProductName ProductID="qemu-ipxe-1.0.0+-150200.79.1">qemu-ipxe-1.0.0+-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-kvm-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-kvm-4.2.1-150200.79.1">qemu-kvm-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-lang-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-lang-4.2.1-150200.79.1">qemu-lang-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-linux-user-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-linux-user-4.2.1-150200.79.1">qemu-linux-user-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-microvm-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-microvm-4.2.1-150200.79.1">qemu-microvm-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ppc-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-ppc-4.2.1-150200.79.1">qemu-ppc-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-s390-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-s390-4.2.1-150200.79.1">qemu-s390-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-seabios-1.12.1+-150200.79.1">
      <FullProductName ProductID="qemu-seabios-1.12.1+-150200.79.1">qemu-seabios-1.12.1+-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-sgabios-8-150200.79.1">
      <FullProductName ProductID="qemu-sgabios-8-150200.79.1">qemu-sgabios-8-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-testsuite-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-testsuite-4.2.1-150200.79.1">qemu-testsuite-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-tools-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-tools-4.2.1-150200.79.1">qemu-tools-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-curses-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-ui-curses-4.2.1-150200.79.1">qemu-ui-curses-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-gtk-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-ui-gtk-4.2.1-150200.79.1">qemu-ui-gtk-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-spice-app-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-ui-spice-app-4.2.1-150200.79.1">qemu-ui-spice-app-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vgabios-1.12.1+-150200.79.1">
      <FullProductName ProductID="qemu-vgabios-1.12.1+-150200.79.1">qemu-vgabios-1.12.1+-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vhost-user-gpu-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-vhost-user-gpu-4.2.1-150200.79.1">qemu-vhost-user-gpu-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-x86-4.2.1-150200.79.1">
      <FullProductName ProductID="qemu-x86-4.2.1-150200.79.1">qemu-x86-4.2.1-150200.79.1</FullProductName>
    </Branch>
    <Relationship ProductReference="qemu-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1">qemu-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1">qemu-arm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1">qemu-audio-alsa-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1">qemu-audio-pa-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1">qemu-block-curl-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1">qemu-block-iscsi-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1">qemu-block-rbd-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1">qemu-block-ssh-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1">qemu-guest-agent-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1">qemu-ipxe-1.0.0+-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1">qemu-kvm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1">qemu-lang-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-microvm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1">qemu-microvm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.12.1+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1">qemu-seabios-1.12.1+-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1">qemu-sgabios-8-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1">qemu-tools-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1">qemu-ui-curses-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1">qemu-ui-gtk-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-spice-app-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1">qemu-ui-spice-app-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.12.1+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1">qemu-vgabios-1.12.1+-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1">qemu-x86-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1">qemu-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1">qemu-arm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1">qemu-audio-alsa-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1">qemu-audio-pa-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1">qemu-block-curl-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1">qemu-block-iscsi-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1">qemu-block-rbd-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1">qemu-block-ssh-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1">qemu-guest-agent-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1">qemu-ipxe-1.0.0+-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1">qemu-kvm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1">qemu-lang-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-microvm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1">qemu-microvm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1">qemu-ppc-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1">qemu-s390-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.12.1+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1">qemu-seabios-1.12.1+-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1">qemu-sgabios-8-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1">qemu-tools-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1">qemu-ui-curses-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1">qemu-ui-gtk-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-spice-app-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1">qemu-ui-spice-app-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.12.1+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1">qemu-vgabios-1.12.1+-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1">qemu-x86-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1">qemu-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1">qemu-audio-alsa-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1">qemu-audio-pa-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1">qemu-block-curl-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1">qemu-block-iscsi-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1">qemu-block-rbd-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1">qemu-block-ssh-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1">qemu-guest-agent-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1">qemu-ipxe-1.0.0+-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1">qemu-kvm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1">qemu-lang-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-microvm-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1">qemu-microvm-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1">qemu-ppc-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.12.1+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1">qemu-seabios-1.12.1+-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1">qemu-sgabios-8-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1">qemu-tools-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1">qemu-ui-curses-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1">qemu-ui-gtk-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-spice-app-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1">qemu-ui-spice-app-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.12.1+-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1">qemu-vgabios-1.12.1+-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1">qemu-x86-4.2.1-150200.79.1 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-4.2.1-150200.79.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1">qemu-s390-4.2.1-150200.79.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.</Note>
    </Notes>
    <CVE>CVE-2020-13754</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.9</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13754.html</URL>
        <Description>CVE-2020-13754</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172382</URL>
        <Description>SUSE Bug 1172382</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2021-3638</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3638.html</URL>
        <Description>CVE-2021-3638</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1188609</URL>
        <Description>SUSE Bug 1188609</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.</Note>
    </Notes>
    <CVE>CVE-2021-3750</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3750.html</URL>
        <Description>CVE-2021-3750</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190011</URL>
        <Description>SUSE Bug 1190011</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1190015</URL>
        <Description>SUSE Bug 1190015</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193880</URL>
        <Description>SUSE Bug 1193880</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.</Note>
    </Notes>
    <CVE>CVE-2021-3929</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>8.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3929.html</URL>
        <Description>CVE-2021-3929</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193880</URL>
        <Description>SUSE Bug 1193880</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.</Note>
    </Notes>
    <CVE>CVE-2022-1050</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>8.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-1050.html</URL>
        <Description>CVE-2022-1050</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1197653</URL>
        <Description>SUSE Bug 1197653</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtqueue before freeing its memory, leading to memory leakage and other unexpected results. Affected QEMU versions &lt;= 6.2.0.</Note>
    </Notes>
    <CVE>CVE-2022-26354</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-26354.html</URL>
        <Description>CVE-2022-26354</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198712</URL>
        <Description>SUSE Bug 1198712</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like stack overflow or use-after-free.</Note>
    </Notes>
    <CVE>CVE-2023-0330</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-0330.html</URL>
        <Description>CVE-2023-0330</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1207205</URL>
        <Description>SUSE Bug 1207205</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. The 9pfs server did not prohibit opening special files on the host side, potentially allowing a malicious client to escape from the exported 9p tree by creating and opening a device file in the shared folder.</Note>
    </Notes>
    <CVE>CVE-2023-2861</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>7.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-2861.html</URL>
        <Description>CVE-2023-2861</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1212968</URL>
        <Description>SUSE Bug 1212968</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.</Note>
    </Notes>
    <CVE>CVE-2023-3180</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>8.2</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-3180.html</URL>
        <Description>CVE-2023-3180</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1213925</URL>
        <Description>SUSE Bug 1213925</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.</Note>
    </Notes>
    <CVE>CVE-2023-3354</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-arm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-s390-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-alsa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-audio-pa-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-curl-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-iscsi-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-rbd-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-block-ssh-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-guest-agent-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ipxe-1.0.0+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-kvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-lang-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-microvm-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ppc-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-seabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-sgabios-8-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-tools-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-curses-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-gtk-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-ui-spice-app-4.2.1-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-vgabios-1.12.1+-150200.79.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:qemu-x86-4.2.1-150200.79.1</ProductID>
        <ProductID>openSUSE Leap 15.4:qemu-s390-4.2.1-150200.79.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>7.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20233721-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-3354.html</URL>
        <Description>CVE-2023-3354</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1212850</URL>
        <Description>SUSE Bug 1212850</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
