QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.
Security Fix(es):
A security vulnerability exists in QEMU, the details of which have not been fully disclosed.(CVE-2026-15578)
CVE-2026-15705 is an undisclosed vulnerability in QEMU. The vulnerability has been identified in QEMU, but specific technical details and impact scope have not yet been publicly disclosed.(CVE-2026-15705)
A security vulnerability exists in QEMU. Detailed vulnerability information has not yet been disclosed. This vulnerability affects all versions.(CVE-2026-16043)
In the Linux kernel, the following vulnerabilities have been addressed: bpf: Support hardened BPF for JIT injection. The JIT allocator packages many small programs into larger executable allocations and reuses space in these allocations, loading and freeing them just like programs. When new code is written to the space of the previous code, the program is occupied, and indirect jumps to the new program can reuse the oracles left by the old oracles in the branch. Flush indirect branch predictors before reusing JIT memory so that indirect jumps to a newly written program do not reuse predictions from an old program that occupies the same space. Introduced bpfarchpredflushenabled static key and bpfarchpred_flush static call for refreshing the branch predictor of JIT memory reuse. Schemas that need to be refreshed can update them with the predictor refresh function. By default, it is a NOP and no CALLs will be issued. Allocations larger than the package are not covered by this flush. That's safe because the cBPF program (unprivileged attack surface) is well constrained below the package size. If this assumption is violated, a warning is issued while flushing is active.(CVE-2026-61475)
An undisclosed vulnerability exists in QEMU, with no detailed vulnerability description available at this time.(CVE-2026-63319)
An undisclosed vulnerability exists in QEMU. Currently, only limited vulnerability information is available, and the specific impact scope and details have not been publicly disclosed.(CVE-2026-8348)
An undisclosed vulnerability exists in QEMU, the details of which have not yet been publicly disclosed.(CVE-2026-9238)
{
"severity": "High"
}{
"x86_64": [
"qemu-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-block-curl-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-block-iscsi-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-block-rbd-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-block-ssh-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-debuginfo-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-debugsource-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-guest-agent-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-hw-usb-host-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-img-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-seabios-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-system-aarch64-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-system-arm-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-system-riscv-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-system-x86_64-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-user-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-user-binfmt-8.2.0-83.oe2403sp4.x86_64.rpm",
"qemu-user-static-8.2.0-83.oe2403sp4.x86_64.rpm"
],
"noarch": [
"qemu-help-8.2.0-83.oe2403sp4.noarch.rpm"
],
"src": [
"qemu-8.2.0-83.oe2403sp4.src.rpm"
],
"aarch64": [
"qemu-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-block-curl-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-block-iscsi-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-block-rbd-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-block-ssh-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-debuginfo-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-debugsource-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-guest-agent-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-hw-usb-host-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-img-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-system-aarch64-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-system-arm-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-system-riscv-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-system-x86_64-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-user-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-user-binfmt-8.2.0-83.oe2403sp4.aarch64.rpm",
"qemu-user-static-8.2.0-83.oe2403sp4.aarch64.rpm"
]
}