<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for qemu</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:0363-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-03-01T06:22:41Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-03-01T06:22:41Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-03-01T06:22:41Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for qemu</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for qemu fixes the following issues:

- Fixed potential privilege escalation in virtfs (CVE-2021-20181 bsc#1182137)
- Fixed out-of-bound access in iscsi (CVE-2020-11947 bsc#1180523)
- Fixed out-of-bound access in vmxnet3 emulation (CVE-2021-20203 bsc#1181639)
- Fixed out-of-bound access in ARM interrupt handling (CVE-2021-20221 bsc#1181933)
- Fixed vfio-pci device on s390 enters error state (bsc#1179717 bsc#1179719)
- Fixed 'Failed to try-restart qemu-ga@.service' error while updating the
  qemu-guest-agent. (bsc#1178565)
- Apply fixes to qemu scsi passthrough with respect to timeout and
  error conditions, including using more correct status codes. Add
  more qemu tracing which helped track down these issues
  (bsc#1178049)

This update was imported from the SUSE:SLE-15-SP2:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2021-363</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:0363-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178049</URL>
      <Description>SUSE Bug 1178049</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178565</URL>
      <Description>SUSE Bug 1178565</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179717</URL>
      <Description>SUSE Bug 1179717</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179719</URL>
      <Description>SUSE Bug 1179719</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1180523</URL>
      <Description>SUSE Bug 1180523</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181639</URL>
      <Description>SUSE Bug 1181639</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181933</URL>
      <Description>SUSE Bug 1181933</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182137</URL>
      <Description>SUSE Bug 1182137</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-11947/</URL>
      <Description>SUSE CVE CVE-2020-11947 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20181/</URL>
      <Description>SUSE CVE CVE-2021-20181 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20203/</URL>
      <Description>SUSE CVE CVE-2021-20203 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20221/</URL>
      <Description>SUSE CVE CVE-2021-20221 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 15.2">
      <Branch Type="Product Name" Name="openSUSE Leap 15.2">
        <FullProductName ProductID="openSUSE Leap 15.2" CPE="cpe:/o:opensuse:leap:15.2">openSUSE Leap 15.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="qemu-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-4.2.1-lp152.9.9.2">qemu-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-arm-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-arm-4.2.1-lp152.9.9.2">qemu-arm-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-alsa-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-audio-alsa-4.2.1-lp152.9.9.2">qemu-audio-alsa-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-pa-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-audio-pa-4.2.1-lp152.9.9.2">qemu-audio-pa-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-sdl-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-audio-sdl-4.2.1-lp152.9.9.2">qemu-audio-sdl-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-curl-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-curl-4.2.1-lp152.9.9.2">qemu-block-curl-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-dmg-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-dmg-4.2.1-lp152.9.9.2">qemu-block-dmg-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-gluster-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-gluster-4.2.1-lp152.9.9.2">qemu-block-gluster-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-iscsi-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-iscsi-4.2.1-lp152.9.9.2">qemu-block-iscsi-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-nfs-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-nfs-4.2.1-lp152.9.9.2">qemu-block-nfs-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-rbd-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-rbd-4.2.1-lp152.9.9.2">qemu-block-rbd-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-ssh-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-block-ssh-4.2.1-lp152.9.9.2">qemu-block-ssh-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-extra-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-extra-4.2.1-lp152.9.9.2">qemu-extra-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-guest-agent-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-guest-agent-4.2.1-lp152.9.9.2">qemu-guest-agent-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ipxe-1.0.0+-lp152.9.9.2">
      <FullProductName ProductID="qemu-ipxe-1.0.0+-lp152.9.9.2">qemu-ipxe-1.0.0+-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ksm-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-ksm-4.2.1-lp152.9.9.2">qemu-ksm-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-kvm-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-kvm-4.2.1-lp152.9.9.2">qemu-kvm-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-lang-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-lang-4.2.1-lp152.9.9.2">qemu-lang-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-linux-user-4.2.1-lp152.9.9.3">
      <FullProductName ProductID="qemu-linux-user-4.2.1-lp152.9.9.3">qemu-linux-user-4.2.1-lp152.9.9.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-microvm-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-microvm-4.2.1-lp152.9.9.2">qemu-microvm-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ppc-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-ppc-4.2.1-lp152.9.9.2">qemu-ppc-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-s390-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-s390-4.2.1-lp152.9.9.2">qemu-s390-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-seabios-1.12.1+-lp152.9.9.2">
      <FullProductName ProductID="qemu-seabios-1.12.1+-lp152.9.9.2">qemu-seabios-1.12.1+-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-sgabios-8-lp152.9.9.2">
      <FullProductName ProductID="qemu-sgabios-8-lp152.9.9.2">qemu-sgabios-8-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-testsuite-4.2.1-lp152.9.9.5">
      <FullProductName ProductID="qemu-testsuite-4.2.1-lp152.9.9.5">qemu-testsuite-4.2.1-lp152.9.9.5</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-tools-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-tools-4.2.1-lp152.9.9.2">qemu-tools-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-curses-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-ui-curses-4.2.1-lp152.9.9.2">qemu-ui-curses-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-gtk-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-ui-gtk-4.2.1-lp152.9.9.2">qemu-ui-gtk-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-sdl-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-ui-sdl-4.2.1-lp152.9.9.2">qemu-ui-sdl-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-spice-app-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-ui-spice-app-4.2.1-lp152.9.9.2">qemu-ui-spice-app-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vgabios-1.12.1+-lp152.9.9.2">
      <FullProductName ProductID="qemu-vgabios-1.12.1+-lp152.9.9.2">qemu-vgabios-1.12.1+-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vhost-user-gpu-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-vhost-user-gpu-4.2.1-lp152.9.9.2">qemu-vhost-user-gpu-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-x86-4.2.1-lp152.9.9.2">
      <FullProductName ProductID="qemu-x86-4.2.1-lp152.9.9.2">qemu-x86-4.2.1-lp152.9.9.2</FullProductName>
    </Branch>
    <Relationship ProductReference="qemu-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-4.2.1-lp152.9.9.2">qemu-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-arm-4.2.1-lp152.9.9.2">qemu-arm-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-audio-alsa-4.2.1-lp152.9.9.2">qemu-audio-alsa-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-audio-pa-4.2.1-lp152.9.9.2">qemu-audio-pa-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-sdl-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-audio-sdl-4.2.1-lp152.9.9.2">qemu-audio-sdl-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-curl-4.2.1-lp152.9.9.2">qemu-block-curl-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-dmg-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-dmg-4.2.1-lp152.9.9.2">qemu-block-dmg-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-gluster-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-gluster-4.2.1-lp152.9.9.2">qemu-block-gluster-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-iscsi-4.2.1-lp152.9.9.2">qemu-block-iscsi-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-nfs-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-nfs-4.2.1-lp152.9.9.2">qemu-block-nfs-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-rbd-4.2.1-lp152.9.9.2">qemu-block-rbd-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-block-ssh-4.2.1-lp152.9.9.2">qemu-block-ssh-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-extra-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-extra-4.2.1-lp152.9.9.2">qemu-extra-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-guest-agent-4.2.1-lp152.9.9.2">qemu-guest-agent-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ipxe-1.0.0+-lp152.9.9.2">qemu-ipxe-1.0.0+-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ksm-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ksm-4.2.1-lp152.9.9.2">qemu-ksm-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-kvm-4.2.1-lp152.9.9.2">qemu-kvm-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-lang-4.2.1-lp152.9.9.2">qemu-lang-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-linux-user-4.2.1-lp152.9.9.3" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-linux-user-4.2.1-lp152.9.9.3">qemu-linux-user-4.2.1-lp152.9.9.3 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-microvm-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-microvm-4.2.1-lp152.9.9.2">qemu-microvm-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ppc-4.2.1-lp152.9.9.2">qemu-ppc-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-s390-4.2.1-lp152.9.9.2">qemu-s390-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.12.1+-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-seabios-1.12.1+-lp152.9.9.2">qemu-seabios-1.12.1+-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-sgabios-8-lp152.9.9.2">qemu-sgabios-8-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-testsuite-4.2.1-lp152.9.9.5" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-testsuite-4.2.1-lp152.9.9.5">qemu-testsuite-4.2.1-lp152.9.9.5 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-tools-4.2.1-lp152.9.9.2">qemu-tools-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ui-curses-4.2.1-lp152.9.9.2">qemu-ui-curses-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ui-gtk-4.2.1-lp152.9.9.2">qemu-ui-gtk-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-sdl-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ui-sdl-4.2.1-lp152.9.9.2">qemu-ui-sdl-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-spice-app-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-ui-spice-app-4.2.1-lp152.9.9.2">qemu-ui-spice-app-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.12.1+-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-vgabios-1.12.1+-lp152.9.9.2">qemu-vgabios-1.12.1+-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vhost-user-gpu-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-vhost-user-gpu-4.2.1-lp152.9.9.2">qemu-vhost-user-gpu-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-4.2.1-lp152.9.9.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:qemu-x86-4.2.1-lp152.9.9.2">qemu-x86-4.2.1-lp152.9.9.2 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.</Note>
    </Notes>
    <CVE>CVE-2020-11947</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.2:qemu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-arm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-alsa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-pa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-curl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-dmg-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-gluster-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-iscsi-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-nfs-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-rbd-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-ssh-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-extra-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-guest-agent-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ipxe-1.0.0+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ksm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-kvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-lang-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-linux-user-4.2.1-lp152.9.9.3</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-microvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ppc-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-s390-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-seabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-sgabios-8-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-testsuite-4.2.1-lp152.9.9.5</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-tools-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-curses-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-gtk-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-spice-app-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vgabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vhost-user-gpu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-x86-4.2.1-lp152.9.9.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-11947.html</URL>
        <Description>CVE-2020-11947</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180523</URL>
        <Description>SUSE Bug 1180523</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20181</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.2:qemu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-arm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-alsa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-pa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-curl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-dmg-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-gluster-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-iscsi-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-nfs-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-rbd-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-ssh-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-extra-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-guest-agent-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ipxe-1.0.0+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ksm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-kvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-lang-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-linux-user-4.2.1-lp152.9.9.3</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-microvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ppc-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-s390-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-seabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-sgabios-8-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-testsuite-4.2.1-lp152.9.9.5</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-tools-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-curses-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-gtk-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-spice-app-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vgabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vhost-user-gpu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-x86-4.2.1-lp152.9.9.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20181.html</URL>
        <Description>CVE-2021-20181</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182137</URL>
        <Description>SUSE Bug 1182137</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.</Note>
    </Notes>
    <CVE>CVE-2021-20203</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.2:qemu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-arm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-alsa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-pa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-curl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-dmg-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-gluster-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-iscsi-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-nfs-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-rbd-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-ssh-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-extra-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-guest-agent-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ipxe-1.0.0+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ksm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-kvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-lang-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-linux-user-4.2.1-lp152.9.9.3</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-microvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ppc-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-s390-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-seabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-sgabios-8-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-testsuite-4.2.1-lp152.9.9.5</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-tools-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-curses-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-gtk-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-spice-app-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vgabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vhost-user-gpu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-x86-4.2.1-lp152.9.9.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20203.html</URL>
        <Description>CVE-2021-20203</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181639</URL>
        <Description>SUSE Bug 1181639</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.</Note>
    </Notes>
    <CVE>CVE-2021-20221</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.2:qemu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-arm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-alsa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-pa-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-audio-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-curl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-dmg-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-gluster-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-iscsi-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-nfs-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-rbd-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-block-ssh-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-extra-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-guest-agent-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ipxe-1.0.0+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ksm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-kvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-lang-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-linux-user-4.2.1-lp152.9.9.3</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-microvm-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ppc-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-s390-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-seabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-sgabios-8-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-testsuite-4.2.1-lp152.9.9.5</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-tools-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-curses-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-gtk-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-sdl-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-ui-spice-app-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vgabios-1.12.1+-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-vhost-user-gpu-4.2.1-lp152.9.9.2</ProductID>
        <ProductID>openSUSE Leap 15.2:qemu-x86-4.2.1-lp152.9.9.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SDUPZEIOIEXWFR2ZTWFFOIO2ZA3AI3VM/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20221.html</URL>
        <Description>CVE-2021-20221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181933</URL>
        <Description>SUSE Bug 1181933</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
