<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for qemu is now available for openEuler-24.03-LTS-SP4</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-3845</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-09-14</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-09-14</InitialReleaseDate>
		<CurrentReleaseDate>2026-09-14</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-09-14</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">qemu security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for qemu is now available for openEuler-24.03-LTS-SP4</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

Security Fix(es):

An unknown vulnerability exists in QEMU, with no detailed description available at this time.(CVE-2026-15264)

CVE-2026-16457 is a security vulnerability in QEMU. The specific details of this vulnerability have not been fully disclosed. This vulnerability may affect the normal operation of the QEMU virtualization platform and poses potential security risks.(CVE-2026-16457)

CVE-2026-18054 is a vulnerability in QEMU, details are not yet disclosed.(CVE-2026-18054)

This update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from
10.2.4(CVE-2026-3890)

This update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from 10.2.4. This vulnerability (CVE-2026-48004) is one of them.(CVE-2026-48004)

QEMU&amp;#39;s virtio-rng frontend does not cancel or detach an RngRequest that is still pending on the rng-random backend before releasing the VirtIORNG object in virtio_rng_device_unrealize(). When a virtio-rng device is hot-plugged (device_del) and there are still entropy requests pending, the delayed backend completion calls the chr_read callback on the released object, causing the host heap to be use-after-free. An attacker able to trigger hot-plugging of the device could exploit this memory security flaw to compromise the QEMU process, causing a denial of service or potential code execution on the host.(CVE-2026-50624)

An unknown vulnerability exists in QEMU, details are not yet disclosed.(CVE-2026-50626)

No detailed vulnerability information available.(CVE-2026-61402)

An unspecified vulnerability exists in QEMU, with no detailed information available at this time.(CVE-2026-61476)

CVE-2026-63109 is a vulnerability in QEMU. Details of this vulnerability have not been publicly disclosed yet.(CVE-2026-63109)

No detailed description available.(CVE-2026-63110)

An unknown vulnerability exists in QEMU, the details of which have not yet been disclosed. Attackers may exploit this vulnerability to cause unknown impacts.(CVE-2026-63320)

An unknown vulnerability exists in QEMU, the details of which have not yet been disclosed. Attackers may exploit this vulnerability to cause unknown impacts.(CVE-2026-63321)

When QEMU&amp;#39;s uefi-vars-x64 virtual device processes the VarCheckPolicy REGISTER command, the uefi_vars_mm_check_policy_register() function directly reads pe-&gt;size without first verifying whether the request length contains the complete variable_policy_entry header. The guest can send a REGISTER request with a length of exactly sizeof(mm_check_policy) (excluding variable_policy_entry), causing the func pointer to cross the end of the allocated MM communication buffer, causing the host heap buffer to read out of bounds (heap-buffer-overflow). An attacker could exploit this memory security flaw to compromise the QEMU process, causing a denial of service or potential code execution on the host.(CVE-2026-63322)

An undisclosed vulnerability exists in QEMU, the details of which are not yet publicly available.(CVE-2026-63323)

An unknown type vulnerability exists in QEMU (Quick Emulator). The specific details have not been disclosed yet.(CVE-2026-65928)

CVE-2026-65929 is a security vulnerability affecting QEMU, with no detailed technical information disclosed yet.(CVE-2026-65929)

QEMU (Quick Emulator) is an open-source machine emulator and virtualizer widely used to run operating systems for different architectures. CVE-2026-66021 is a security vulnerability affecting QEMU, with specific details not yet fully disclosed.(CVE-2026-66021)

An unspecified vulnerability exists in QEMU, the details of which have not been disclosed.(CVE-2026-66022)

QEMU&amp;#39;s VNC extended clipboard handler, after decompressing a client-controlled clipboard payload, compares the declared text size to the entire decompression buffer size, but then copies tsize bytes from buf + 4. The correct boundary is the remaining data length after the 4-byte length field. Therefore, a VNC client can cause QEMU to read up to 3 bytes out of bounds from the end of the decompressed heap buffer; a second VNC client can observe these bytes through the normal VNC extended clipboard PROVIDE path.(CVE-2026-8343)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for qemu is now available for master/openEuler-20.03-LTS-SP4/openEuler-24.03-LTS-SP4.

openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">High</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">qemu</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-15264</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-16457</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-18054</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-3890</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-48004</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-50624</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-50626</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-61402</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-61476</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63109</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63110</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63320</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63321</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63322</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63323</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-65928</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-65929</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-66021</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-66022</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8343</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-15264</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-16457</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-18054</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-3890</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-48004</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-50624</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-50626</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-61402</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-61476</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63109</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63110</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63320</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63321</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63322</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63323</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-65928</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-65929</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-66021</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-66022</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-8343</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-24.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">openEuler-24.03-LTS-SP4</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="qemu-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-curl-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-curl-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-iscsi-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-iscsi-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-rbd-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-rbd-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-ssh-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-ssh-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debuginfo-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-debuginfo-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debugsource-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-debugsource-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-guest-agent-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-guest-agent-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-hw-usb-host-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-hw-usb-host-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-img-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-img-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-aarch64-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-aarch64-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-arm-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-arm-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-riscv-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-riscv-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-x86_64-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-x86_64-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-user-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-user-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-user-binfmt-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-user-binfmt-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-user-static-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-user-static-8.2.0-86.oe2403sp4.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="qemu-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-8.2.0-86.oe2403sp4.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="qemu-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-curl-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-curl-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-iscsi-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-iscsi-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-rbd-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-rbd-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-ssh-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-block-ssh-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debuginfo-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-debuginfo-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debugsource-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-debugsource-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-guest-agent-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-guest-agent-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-hw-usb-host-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-hw-usb-host-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-img-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-img-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-seabios-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-seabios-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-aarch64-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-aarch64-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-arm-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-arm-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-riscv-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-riscv-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-x86_64-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-system-x86_64-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-user-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-user-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-user-binfmt-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-user-binfmt-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-user-static-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-user-static-8.2.0-86.oe2403sp4.x86_64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="noarch">
			<FullProductName ProductID="qemu-help-8.2.0-86" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">qemu-help-8.2.0-86.oe2403sp4.noarch.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unknown vulnerability exists in QEMU, with no detailed description available at this time.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-15264</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>8.8</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CVE-2026-16457 is a security vulnerability in QEMU. The specific details of this vulnerability have not been fully disclosed. This vulnerability may affect the normal operation of the QEMU virtualization platform and poses potential security risks.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-16457</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.5</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CVE-2026-18054 is a vulnerability in QEMU, details are not yet disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-18054</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.8</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">This update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from
10.2.4</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-3890</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.5</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">This update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from 10.2.4. This vulnerability (CVE-2026-48004) is one of them.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-48004</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>4.7</BaseScore>
				<Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">QEMU&amp;#39;s virtio-rng frontend does not cancel or detach an RngRequest that is still pending on the rng-random backend before releasing the VirtIORNG object in virtio_rng_device_unrealize(). When a virtio-rng device is hot-plugged (device_del) and there are still entropy requests pending, the delayed backend completion calls the chr_read callback on the released object, causing the host heap to be use-after-free. An attacker able to trigger hot-plugging of the device could exploit this memory security flaw to compromise the QEMU process, causing a denial of service or potential code execution on the host.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-50624</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>4.1</BaseScore>
				<Vector>AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unknown vulnerability exists in QEMU, details are not yet disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-50626</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>8.8</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">No detailed vulnerability information available.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-61402</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.1</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unspecified vulnerability exists in QEMU, with no detailed information available at this time.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-61476</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.5</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CVE-2026-63109 is a vulnerability in QEMU. Details of this vulnerability have not been publicly disclosed yet.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-63109</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.8</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">No detailed description available.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-63110</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.4</BaseScore>
				<Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unknown vulnerability exists in QEMU, the details of which have not yet been disclosed. Attackers may exploit this vulnerability to cause unknown impacts.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-63320</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.3</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unknown vulnerability exists in QEMU, the details of which have not yet been disclosed. Attackers may exploit this vulnerability to cause unknown impacts.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-63321</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.2</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">When QEMU&amp;#39;s uefi-vars-x64 virtual device processes the VarCheckPolicy REGISTER command, the uefi_vars_mm_check_policy_register() function directly reads pe-&gt;size without first verifying whether the request length contains the complete variable_policy_entry header. The guest can send a REGISTER request with a length of exactly sizeof(mm_check_policy) (excluding variable_policy_entry), causing the func pointer to cross the end of the allocated MM communication buffer, causing the host heap buffer to read out of bounds (heap-buffer-overflow). An attacker could exploit this memory security flaw to compromise the QEMU process, causing a denial of service or potential code execution on the host.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-63322</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>4.4</BaseScore>
				<Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An undisclosed vulnerability exists in QEMU, the details of which are not yet publicly available.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-63323</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.0</BaseScore>
				<Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unknown type vulnerability exists in QEMU (Quick Emulator). The specific details have not been disclosed yet.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-65928</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>4.4</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CVE-2026-65929 is a security vulnerability affecting QEMU, with no detailed technical information disclosed yet.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-65929</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.5</BaseScore>
				<Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">QEMU (Quick Emulator) is an open-source machine emulator and virtualizer widely used to run operating systems for different architectures. CVE-2026-66021 is a security vulnerability affecting QEMU, with specific details not yet fully disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-66021</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.3</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An unspecified vulnerability exists in QEMU, the details of which have not been disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-66022</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.8</BaseScore>
				<Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">QEMU&amp;#39;s VNC extended clipboard handler, after decompressing a client-controlled clipboard payload, compares the declared text size to the entire decompression buffer size, but then copies tsize bytes from buf + 4. The correct boundary is the remaining data length after the 4-byte length field. Therefore, a VNC client can cause QEMU to read up to 3 bytes out of bounds from the end of the decompressed heap buffer; a second VNC client can observe these bytes through the normal VNC extended clipboard PROVIDE path.</Note>
		</Notes>
		<ReleaseDate>2026-09-14</ReleaseDate>
		<CVE>CVE-2026-8343</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.3</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-09-14</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3845</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>