<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for qemu</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:1947-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-06-10T10:31:38Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-06-10T10:31:38Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-06-10T10:31:38Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for qemu</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for qemu fixes the following issues:

- Fix OOB access during mmio operations (CVE-2020-13754, bsc#1172382)
- Fix out-of-bounds read information disclosure in icmp6_send_echoreply (CVE-2020-10756, bsc#1172380)
- For the record, these issues are fixed in this package already.
  Most are alternate references to previously mentioned issues:
  (CVE-2019-15890, bsc#1149813, CVE-2020-8608, bsc#1163019,
  CVE-2020-14364, bsc#1175534, CVE-2020-25707, bsc#1178683,
  CVE-2020-25723, bsc#1178935, CVE-2020-29130, bsc#1179477,
  CVE-2020-29129, bsc#1179484, CVE-2021-20257, bsc#1182846,
  CVE-2021-3419, bsc#1182975)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2021-1947,SUSE-OpenStack-Cloud-9-2021-1947,SUSE-OpenStack-Cloud-Crowbar-9-2021-1947,SUSE-SLE-SAP-12-SP4-2021-1947,SUSE-SLE-SERVER-12-SP4-LTSS-2021-1947</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      <Description>Link for SUSE-SU-2021:1947-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-June/008990.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:1947-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1149813</URL>
      <Description>SUSE Bug 1149813</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1163019</URL>
      <Description>SUSE Bug 1163019</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172380</URL>
      <Description>SUSE Bug 1172380</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172382</URL>
      <Description>SUSE Bug 1172382</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1175534</URL>
      <Description>SUSE Bug 1175534</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178683</URL>
      <Description>SUSE Bug 1178683</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178935</URL>
      <Description>SUSE Bug 1178935</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179477</URL>
      <Description>SUSE Bug 1179477</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179484</URL>
      <Description>SUSE Bug 1179484</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182846</URL>
      <Description>SUSE Bug 1182846</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182975</URL>
      <Description>SUSE Bug 1182975</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-15890/</URL>
      <Description>SUSE CVE CVE-2019-15890 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-10756/</URL>
      <Description>SUSE CVE CVE-2020-10756 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13754/</URL>
      <Description>SUSE CVE CVE-2020-13754 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-14364/</URL>
      <Description>SUSE CVE CVE-2020-14364 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25707/</URL>
      <Description>SUSE CVE CVE-2020-25707 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25723/</URL>
      <Description>SUSE CVE CVE-2020-25723 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29129/</URL>
      <Description>SUSE CVE CVE-2020-29129 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29130/</URL>
      <Description>SUSE CVE CVE-2020-29130 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-8608/</URL>
      <Description>SUSE CVE CVE-2020-8608 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20257/</URL>
      <Description>SUSE CVE CVE-2021-20257 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3419/</URL>
      <Description>SUSE CVE CVE-2021-3419 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP4-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS" CPE="cpe:/o:suse:sles-ltss:12:sp4">SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4" CPE="cpe:/o:suse:sles_sap:12:sp4">SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 9">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 9">
        <FullProductName ProductID="SUSE OpenStack Cloud 9" CPE="cpe:/o:suse:suse-openstack-cloud:9">SUSE OpenStack Cloud 9</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud Crowbar 9">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud Crowbar 9">
        <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9" CPE="cpe:/o:suse:suse-openstack-cloud-crowbar:9">SUSE OpenStack Cloud Crowbar 9</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="qemu-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-2.11.2-5.32.1">qemu-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-arm-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-arm-2.11.2-5.32.1">qemu-arm-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-curl-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-block-curl-2.11.2-5.32.1">qemu-block-curl-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-dmg-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-block-dmg-2.11.2-5.32.1">qemu-block-dmg-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-iscsi-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-block-iscsi-2.11.2-5.32.1">qemu-block-iscsi-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-rbd-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-block-rbd-2.11.2-5.32.1">qemu-block-rbd-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-ssh-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-block-ssh-2.11.2-5.32.1">qemu-block-ssh-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-extra-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-extra-2.11.2-5.32.1">qemu-extra-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-guest-agent-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-guest-agent-2.11.2-5.32.1">qemu-guest-agent-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ipxe-1.0.0+-5.32.1">
      <FullProductName ProductID="qemu-ipxe-1.0.0+-5.32.1">qemu-ipxe-1.0.0+-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-kvm-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-kvm-2.11.2-5.32.1">qemu-kvm-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-lang-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-lang-2.11.2-5.32.1">qemu-lang-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-linux-user-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-linux-user-2.11.2-5.32.1">qemu-linux-user-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ppc-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-ppc-2.11.2-5.32.1">qemu-ppc-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-s390-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-s390-2.11.2-5.32.1">qemu-s390-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-seabios-1.11.0_0_g63451fc-5.32.1">
      <FullProductName ProductID="qemu-seabios-1.11.0_0_g63451fc-5.32.1">qemu-seabios-1.11.0_0_g63451fc-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-sgabios-8-5.32.1">
      <FullProductName ProductID="qemu-sgabios-8-5.32.1">qemu-sgabios-8-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-tools-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-tools-2.11.2-5.32.1">qemu-tools-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vgabios-1.11.0_0_g63451fc-5.32.1">
      <FullProductName ProductID="qemu-vgabios-1.11.0_0_g63451fc-5.32.1">qemu-vgabios-1.11.0_0_g63451fc-5.32.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-x86-2.11.2-5.32.1">
      <FullProductName ProductID="qemu-x86-2.11.2-5.32.1">qemu-x86-2.11.2-5.32.1</FullProductName>
    </Branch>
    <Relationship ProductReference="qemu-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1">qemu-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1">qemu-arm-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1">qemu-block-curl-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1">qemu-block-iscsi-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1">qemu-block-rbd-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1">qemu-block-ssh-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1">qemu-guest-agent-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1">qemu-ipxe-1.0.0+-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1">qemu-kvm-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1">qemu-lang-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1">qemu-ppc-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1">qemu-s390-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1">qemu-seabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1">qemu-sgabios-8-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1">qemu-tools-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1">qemu-vgabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP4-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1">qemu-x86-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server 12 SP4-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1">qemu-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1">qemu-block-curl-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1">qemu-block-iscsi-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1">qemu-block-rbd-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1">qemu-block-ssh-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1">qemu-guest-agent-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1">qemu-ipxe-1.0.0+-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1">qemu-kvm-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1">qemu-lang-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1">qemu-ppc-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1">qemu-seabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1">qemu-sgabios-8-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1">qemu-tools-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1">qemu-vgabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1">qemu-x86-2.11.2-5.32.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1">qemu-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1">qemu-block-curl-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1">qemu-block-iscsi-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1">qemu-block-rbd-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1">qemu-block-ssh-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1">qemu-guest-agent-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1">qemu-ipxe-1.0.0+-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1">qemu-kvm-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1">qemu-lang-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1">qemu-seabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1">qemu-sgabios-8-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1">qemu-tools-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1">qemu-vgabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 9">
      <FullProductName ProductID="SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1">qemu-x86-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1">qemu-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1">qemu-block-curl-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1">qemu-block-iscsi-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1">qemu-block-rbd-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1">qemu-block-ssh-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1">qemu-guest-agent-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1">qemu-ipxe-1.0.0+-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1">qemu-kvm-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1">qemu-lang-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1">qemu-seabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1">qemu-sgabios-8-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1">qemu-tools-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.11.0_0_g63451fc-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1">qemu-vgabios-1.11.0_0_g63451fc-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-2.11.2-5.32.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud Crowbar 9">
      <FullProductName ProductID="SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1">qemu-x86-2.11.2-5.32.1 as a component of SUSE OpenStack Cloud Crowbar 9</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.</Note>
    </Notes>
    <CVE>CVE-2019-15890</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-15890.html</URL>
        <Description>CVE-2019-15890</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149811</URL>
        <Description>SUSE Bug 1149811</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1149813</URL>
        <Description>SUSE Bug 1149813</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.</Note>
    </Notes>
    <CVE>CVE-2020-10756</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-10756.html</URL>
        <Description>CVE-2020-10756</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172380</URL>
        <Description>SUSE Bug 1172380</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1184743</URL>
        <Description>SUSE Bug 1184743</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.</Note>
    </Notes>
    <CVE>CVE-2020-13754</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.6</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13754.html</URL>
        <Description>CVE-2020-13754</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172382</URL>
        <Description>SUSE Bug 1172382</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.</Note>
    </Notes>
    <CVE>CVE-2020-14364</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.4</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-14364.html</URL>
        <Description>CVE-2020-14364</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175441</URL>
        <Description>SUSE Bug 1175441</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1175534</URL>
        <Description>SUSE Bug 1175534</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1176494</URL>
        <Description>SUSE Bug 1176494</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1177130</URL>
        <Description>SUSE Bug 1177130</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate is a duplicate of CVE-2020-2891</Note>
    </Notes>
    <CVE>CVE-2020-25707</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25707.html</URL>
        <Description>CVE-2020-25707</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178683</URL>
        <Description>SUSE Bug 1178683</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179468</URL>
        <Description>SUSE Bug 1179468</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2020-25723</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25723.html</URL>
        <Description>CVE-2020-25723</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178934</URL>
        <Description>SUSE Bug 1178934</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178935</URL>
        <Description>SUSE Bug 1178935</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.</Note>
    </Notes>
    <CVE>CVE-2020-29129</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29129.html</URL>
        <Description>CVE-2020-29129</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179466</URL>
        <Description>SUSE Bug 1179466</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179467</URL>
        <Description>SUSE Bug 1179467</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179477</URL>
        <Description>SUSE Bug 1179477</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179484</URL>
        <Description>SUSE Bug 1179484</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.</Note>
    </Notes>
    <CVE>CVE-2020-29130</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29130.html</URL>
        <Description>CVE-2020-29130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179467</URL>
        <Description>SUSE Bug 1179467</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179477</URL>
        <Description>SUSE Bug 1179477</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.</Note>
    </Notes>
    <CVE>CVE-2020-8608</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-8608.html</URL>
        <Description>CVE-2020-8608</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1163018</URL>
        <Description>SUSE Bug 1163018</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1163019</URL>
        <Description>SUSE Bug 1163019</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20257</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20257.html</URL>
        <Description>CVE-2021-20257</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182577</URL>
        <Description>SUSE Bug 1182577</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182846</URL>
        <Description>SUSE Bug 1182846</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none</Note>
    </Notes>
    <CVE>CVE-2021-3419</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-arm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-s390-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP4-LTSS:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-ppc-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP4:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 9:qemu-x86-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-curl-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-iscsi-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-rbd-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-block-ssh-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-guest-agent-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-ipxe-1.0.0+-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-kvm-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-lang-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-seabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-sgabios-8-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-tools-2.11.2-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-vgabios-1.11.0_0_g63451fc-5.32.1</ProductID>
        <ProductID>SUSE OpenStack Cloud Crowbar 9:qemu-x86-2.11.2-5.32.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211947-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3419.html</URL>
        <Description>CVE-2021-3419</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182968</URL>
        <Description>SUSE Bug 1182968</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182975</URL>
        <Description>SUSE Bug 1182975</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
