<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for qemu is now available for openEuler-22.03-LTS-SP4</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-3273</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-08-07</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-08-07</InitialReleaseDate>
		<CurrentReleaseDate>2026-08-07</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-08-07</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">qemu security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for qemu is now available for openEuler-22.03-LTS-SP4</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

Security Fix(es):

A security vulnerability exists in QEMU, the details of which have not been fully disclosed.(CVE-2026-15578)

CVE-2026-15705 is an undisclosed vulnerability in QEMU. The vulnerability has been identified in QEMU, but specific technical details and impact scope have not yet been publicly disclosed.(CVE-2026-15705)

A security vulnerability exists in QEMU. Detailed vulnerability information has not yet been disclosed. This vulnerability affects all versions.(CVE-2026-16043)

In the Linux kernel, the following vulnerabilities have been addressed: bpf: Support hardened BPF for JIT injection. The JIT allocator packages many small programs into larger executable allocations and reuses space in these allocations, loading and freeing them just like programs. When new code is written to the space of the previous code, the program is occupied, and indirect jumps to the new program can reuse the oracles left by the old oracles in the branch. Flush indirect branch predictors before reusing JIT memory so that indirect jumps to a newly written program do not reuse predictions from an old program that occupies the same space. Introduced bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush static call for refreshing the branch predictor of JIT memory reuse. Schemas that need to be refreshed can update them with the predictor refresh function. By default, it is a NOP and no CALLs will be issued. Allocations larger than the package are not covered by this flush. That&amp;#39;s safe because the cBPF program (unprivileged attack surface) is well constrained below the package size. If this assumption is violated, a warning is issued while flushing is active.(CVE-2026-61475)

An undisclosed vulnerability exists in QEMU, with no detailed vulnerability description available at this time.(CVE-2026-63319)

An undisclosed vulnerability exists in QEMU. Currently, only limited vulnerability information is available, and the specific impact scope and details have not been publicly disclosed.(CVE-2026-8348)

An undisclosed vulnerability exists in QEMU, the details of which have not yet been publicly disclosed.(CVE-2026-9238)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for qemu is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4.

openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">High</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">qemu</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-15578</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-15705</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-16043</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-61475</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-63319</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-8348</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-9238</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-15578</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-15705</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-16043</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-61475</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-63319</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-8348</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-9238</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-22.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">openEuler-22.03-LTS-SP4</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="qemu-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-curl-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-curl-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-iscsi-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-iscsi-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-rbd-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-rbd-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-ssh-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-ssh-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debuginfo-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-debuginfo-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debugsource-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-debugsource-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-guest-agent-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-guest-agent-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-hw-usb-host-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-hw-usb-host-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-img-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-img-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-aarch64-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-aarch64-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-arm-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-arm-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-riscv-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-riscv-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-x86_64-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-x86_64-6.2.0-117.oe2203sp4.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="qemu-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-6.2.0-117.oe2203sp4.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="qemu-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-curl-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-curl-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-iscsi-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-iscsi-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-rbd-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-rbd-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-block-ssh-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-block-ssh-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debuginfo-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-debuginfo-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-debugsource-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-debugsource-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-guest-agent-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-guest-agent-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-hw-usb-host-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-hw-usb-host-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-img-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-img-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-seabios-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-seabios-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-aarch64-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-aarch64-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-arm-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-arm-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-riscv-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-riscv-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="qemu-system-x86_64-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-system-x86_64-6.2.0-117.oe2203sp4.x86_64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="noarch">
			<FullProductName ProductID="qemu-help-6.2.0-117" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">qemu-help-6.2.0-117.oe2203sp4.noarch.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A security vulnerability exists in QEMU, the details of which have not been fully disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-15578</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.5</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CVE-2026-15705 is an undisclosed vulnerability in QEMU. The vulnerability has been identified in QEMU, but specific technical details and impact scope have not yet been publicly disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-15705</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.4</BaseScore>
				<Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A security vulnerability exists in QEMU. Detailed vulnerability information has not yet been disclosed. This vulnerability affects all versions.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-16043</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>8.2</BaseScore>
				<Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In the Linux kernel, the following vulnerabilities have been addressed: bpf: Support hardened BPF for JIT injection. The JIT allocator packages many small programs into larger executable allocations and reuses space in these allocations, loading and freeing them just like programs. When new code is written to the space of the previous code, the program is occupied, and indirect jumps to the new program can reuse the oracles left by the old oracles in the branch. Flush indirect branch predictors before reusing JIT memory so that indirect jumps to a newly written program do not reuse predictions from an old program that occupies the same space. Introduced bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush static call for refreshing the branch predictor of JIT memory reuse. Schemas that need to be refreshed can update them with the predictor refresh function. By default, it is a NOP and no CALLs will be issued. Allocations larger than the package are not covered by this flush. That&amp;#39;s safe because the cBPF program (unprivileged attack surface) is well constrained below the package size. If this assumption is violated, a warning is issued while flushing is active.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-61475</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.3</BaseScore>
				<Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An undisclosed vulnerability exists in QEMU, with no detailed vulnerability description available at this time.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-63319</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.5</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An undisclosed vulnerability exists in QEMU. Currently, only limited vulnerability information is available, and the specific impact scope and details have not been publicly disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-8348</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.5</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An undisclosed vulnerability exists in QEMU, the details of which have not yet been publicly disclosed.</Note>
		</Notes>
		<ReleaseDate>2026-08-07</ReleaseDate>
		<CVE>CVE-2026-9238</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.8</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>qemu security update</Description>
				<DATE>2026-08-07</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3273</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>