<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for qemu</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2021:1242-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-04-16T12:44:46Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-04-16T12:44:46Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-04-16T12:44:46Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for qemu</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for qemu fixes the following issues:

- Fix OOB access in sm501 device emulation (CVE-2020-12829, bsc#1172385)
- Fix OOB access possibility in MegaRAID SAS 8708EM2 emulation (CVE-2020-13362 bsc#1172383)
- Fix use-after-free in usb xhci packet handling (CVE-2020-25723, bsc#1178934)
- Fix use-after-free in usb iehci packet handling (CVE-2020-25084, bsc#1176673)
- Fix infinite loop (DoS) in usb hcd-ohci emulation (CVE-2020-25625, bsc#1176684)
- Fix OOB access in usb hcd-ohci emulation (CVE-2020-25624, bsc#1176682)
- Fix guest triggerable assert in shared network handling code (CVE-2020-27617, bsc#1178174)
- Fix infinite loop (DoS) in e1000e device emulation (CVE-2020-28916, bsc#1179468)
- Fix OOB access in atapi emulation (CVE-2020-29443, bsc#1181108)
- Fix heap overflow in MSIx emulation (CVE-2020-27821, bsc#1179686)
- Fix null pointer deref. (DoS) in mmio ops (CVE-2020-15469, bsc#1173612)
- Fix infinite loop (DoS) in e1000 device emulation (CVE-2021-20257, bsc#1182577)
- Fix OOB access (stack overflow) in rtl8139 NIC emulation (CVE-2021-3416, bsc#1182968)
- Fix OOB access (stack overflow) in other NIC emulations (CVE-2021-3416)
- Fix OOB access in SLIRP ARP/NCSI packet processing (CVE-2020-29129, bsc#1179466, CVE-2020-29130, bsc#1179467)
- Fix null pointer dereference possibility (DoS) in MegaRAID SAS 8708EM2 emulation (CVE-2020-13659 bsc#1172386)
- Fix issue where s390 guest fails to find zipl boot menu index (bsc#1183979)
- Fix OOB access in iscsi (CVE-2020-11947 bsc#1180523)
- Fix OOB access in vmxnet3 emulation (CVE-2021-20203 bsc#1181639)
- Fix package scripts to not use hard coded paths for temporary working directories and log files (bsc#1182425)
- Fix potential privilege escalation in virtfs (CVE-2021-20181 bsc#1182137)
- Apply fixes to qemu scsi passthrough with respect to timeout and error conditions, including using more correct status codes. (bsc#1178049)
- Fix OOB access in ARM interrupt handling (CVE-2021-20221 bsc#1181933)
- Make note that this patch previously included addresses (CVE-2020-13765 bsc#1172478)
- Tweaks to spec file for better formatting, and remove not needed BuildRequires for e2fsprogs-devel and libpcap-devel
- Fix vfio-pci device on s390 enters error state (bsc#1179725)
- Fix PCI devices are unavailable after a subsystem reset. (bsc#1179726)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES12-SP5-EC2-ECS-On-Demand-2021-1242,SUSE-2021-1242,SUSE-SLE-SERVER-12-SP5-2021-1242</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      <Description>Link for SUSE-SU-2021:1242-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2021-April/008652.html</URL>
      <Description>E-Mail link for SUSE-SU-2021:1242-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172383</URL>
      <Description>SUSE Bug 1172383</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172385</URL>
      <Description>SUSE Bug 1172385</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172386</URL>
      <Description>SUSE Bug 1172386</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1172478</URL>
      <Description>SUSE Bug 1172478</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1173612</URL>
      <Description>SUSE Bug 1173612</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1176673</URL>
      <Description>SUSE Bug 1176673</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1176682</URL>
      <Description>SUSE Bug 1176682</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1176684</URL>
      <Description>SUSE Bug 1176684</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178049</URL>
      <Description>SUSE Bug 1178049</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178174</URL>
      <Description>SUSE Bug 1178174</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178934</URL>
      <Description>SUSE Bug 1178934</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179466</URL>
      <Description>SUSE Bug 1179466</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179467</URL>
      <Description>SUSE Bug 1179467</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179468</URL>
      <Description>SUSE Bug 1179468</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179686</URL>
      <Description>SUSE Bug 1179686</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179725</URL>
      <Description>SUSE Bug 1179725</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179726</URL>
      <Description>SUSE Bug 1179726</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1180523</URL>
      <Description>SUSE Bug 1180523</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181108</URL>
      <Description>SUSE Bug 1181108</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181639</URL>
      <Description>SUSE Bug 1181639</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181933</URL>
      <Description>SUSE Bug 1181933</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182137</URL>
      <Description>SUSE Bug 1182137</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182425</URL>
      <Description>SUSE Bug 1182425</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182577</URL>
      <Description>SUSE Bug 1182577</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1182968</URL>
      <Description>SUSE Bug 1182968</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1183979</URL>
      <Description>SUSE Bug 1183979</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-11947/</URL>
      <Description>SUSE CVE CVE-2020-11947 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-12829/</URL>
      <Description>SUSE CVE CVE-2020-12829 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13362/</URL>
      <Description>SUSE CVE CVE-2020-13362 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13659/</URL>
      <Description>SUSE CVE CVE-2020-13659 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-13765/</URL>
      <Description>SUSE CVE CVE-2020-13765 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-15469/</URL>
      <Description>SUSE CVE CVE-2020-15469 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25084/</URL>
      <Description>SUSE CVE CVE-2020-25084 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25624/</URL>
      <Description>SUSE CVE CVE-2020-25624 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25625/</URL>
      <Description>SUSE CVE CVE-2020-25625 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-25723/</URL>
      <Description>SUSE CVE CVE-2020-25723 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-27617/</URL>
      <Description>SUSE CVE CVE-2020-27617 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-27821/</URL>
      <Description>SUSE CVE CVE-2020-27821 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-28916/</URL>
      <Description>SUSE CVE CVE-2020-28916 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29129/</URL>
      <Description>SUSE CVE CVE-2020-29129 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29130/</URL>
      <Description>SUSE CVE CVE-2020-29130 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29443/</URL>
      <Description>SUSE CVE CVE-2020-29443 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20181/</URL>
      <Description>SUSE CVE CVE-2021-20181 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20203/</URL>
      <Description>SUSE CVE CVE-2021-20203 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20221/</URL>
      <Description>SUSE CVE CVE-2021-20221 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-20257/</URL>
      <Description>SUSE CVE CVE-2021-20257 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3416/</URL>
      <Description>SUSE CVE CVE-2021-3416 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand">Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5" CPE="cpe:/o:suse:sles:12:sp5">SUSE Linux Enterprise Server 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5" CPE="cpe:/o:suse:sles_sap:12:sp5">SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="qemu-tools-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-tools-3.1.1.1-48.2">qemu-tools-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-3.1.1.1-48.2">qemu-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-arm-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-arm-3.1.1.1-48.2">qemu-arm-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-alsa-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-audio-alsa-3.1.1.1-48.2">qemu-audio-alsa-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-oss-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-audio-oss-3.1.1.1-48.2">qemu-audio-oss-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-pa-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-audio-pa-3.1.1.1-48.2">qemu-audio-pa-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-audio-sdl-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-audio-sdl-3.1.1.1-48.2">qemu-audio-sdl-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-curl-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-block-curl-3.1.1.1-48.2">qemu-block-curl-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-dmg-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-block-dmg-3.1.1.1-48.2">qemu-block-dmg-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-iscsi-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-block-iscsi-3.1.1.1-48.2">qemu-block-iscsi-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-rbd-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-block-rbd-3.1.1.1-48.2">qemu-block-rbd-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-block-ssh-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-block-ssh-3.1.1.1-48.2">qemu-block-ssh-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-extra-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-extra-3.1.1.1-48.2">qemu-extra-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-guest-agent-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-guest-agent-3.1.1.1-48.2">qemu-guest-agent-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ipxe-1.0.0+-48.2">
      <FullProductName ProductID="qemu-ipxe-1.0.0+-48.2">qemu-ipxe-1.0.0+-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-kvm-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-kvm-3.1.1.1-48.2">qemu-kvm-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-lang-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-lang-3.1.1.1-48.2">qemu-lang-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-linux-user-3.1.1.1-48.1">
      <FullProductName ProductID="qemu-linux-user-3.1.1.1-48.1">qemu-linux-user-3.1.1.1-48.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ppc-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-ppc-3.1.1.1-48.2">qemu-ppc-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-s390-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-s390-3.1.1.1-48.2">qemu-s390-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-seabios-1.12.0_0_ga698c89-48.2">
      <FullProductName ProductID="qemu-seabios-1.12.0_0_ga698c89-48.2">qemu-seabios-1.12.0_0_ga698c89-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-sgabios-8-48.2">
      <FullProductName ProductID="qemu-sgabios-8-48.2">qemu-sgabios-8-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-curses-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-ui-curses-3.1.1.1-48.2">qemu-ui-curses-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-gtk-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-ui-gtk-3.1.1.1-48.2">qemu-ui-gtk-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-ui-sdl-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-ui-sdl-3.1.1.1-48.2">qemu-ui-sdl-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-vgabios-1.12.0_0_ga698c89-48.2">
      <FullProductName ProductID="qemu-vgabios-1.12.0_0_ga698c89-48.2">qemu-vgabios-1.12.0_0_ga698c89-48.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="qemu-x86-3.1.1.1-48.2">
      <FullProductName ProductID="qemu-x86-3.1.1.1-48.2">qemu-x86-3.1.1.1-48.2</FullProductName>
    </Branch>
    <Relationship ProductReference="qemu-tools-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-ECS-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2">qemu-tools-3.1.1.1-48.2 as a component of Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2">qemu-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2">qemu-arm-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2">qemu-audio-alsa-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-oss-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2">qemu-audio-oss-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2">qemu-audio-pa-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-sdl-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2">qemu-audio-sdl-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2">qemu-block-curl-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2">qemu-block-iscsi-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2">qemu-block-rbd-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2">qemu-block-ssh-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2">qemu-guest-agent-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2">qemu-ipxe-1.0.0+-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2">qemu-kvm-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2">qemu-lang-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2">qemu-ppc-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2">qemu-s390-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.12.0_0_ga698c89-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2">qemu-seabios-1.12.0_0_ga698c89-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2">qemu-sgabios-8-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2">qemu-tools-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2">qemu-ui-curses-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2">qemu-ui-gtk-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-sdl-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2">qemu-ui-sdl-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.12.0_0_ga698c89-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2">qemu-vgabios-1.12.0_0_ga698c89-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2">qemu-x86-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2">qemu-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-arm-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2">qemu-arm-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-alsa-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2">qemu-audio-alsa-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-oss-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2">qemu-audio-oss-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-pa-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2">qemu-audio-pa-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-audio-sdl-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2">qemu-audio-sdl-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-curl-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2">qemu-block-curl-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-iscsi-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2">qemu-block-iscsi-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-rbd-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2">qemu-block-rbd-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-block-ssh-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2">qemu-block-ssh-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-guest-agent-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2">qemu-guest-agent-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ipxe-1.0.0+-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2">qemu-ipxe-1.0.0+-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-kvm-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2">qemu-kvm-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-lang-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2">qemu-lang-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ppc-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2">qemu-ppc-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-s390-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2">qemu-s390-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-seabios-1.12.0_0_ga698c89-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2">qemu-seabios-1.12.0_0_ga698c89-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-sgabios-8-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2">qemu-sgabios-8-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-tools-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2">qemu-tools-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-curses-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2">qemu-ui-curses-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-gtk-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2">qemu-ui-gtk-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-ui-sdl-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2">qemu-ui-sdl-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-vgabios-1.12.0_0_ga698c89-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2">qemu-vgabios-1.12.0_0_ga698c89-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="qemu-x86-3.1.1.1-48.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2">qemu-x86-3.1.1.1-48.2 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.</Note>
    </Notes>
    <CVE>CVE-2020-11947</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-11947.html</URL>
        <Description>CVE-2020-11947</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180523</URL>
        <Description>SUSE Bug 1180523</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2020-12829</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-12829.html</URL>
        <Description>CVE-2020-12829</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172385</URL>
        <Description>SUSE Bug 1172385</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.</Note>
    </Notes>
    <CVE>CVE-2020-13362</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13362.html</URL>
        <Description>CVE-2020-13362</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172383</URL>
        <Description>SUSE Bug 1172383</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.</Note>
    </Notes>
    <CVE>CVE-2020-13659</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>1.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13659.html</URL>
        <Description>CVE-2020-13659</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172386</URL>
        <Description>SUSE Bug 1172386</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation.</Note>
    </Notes>
    <CVE>CVE-2020-13765</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-13765.html</URL>
        <Description>CVE-2020-13765</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1172478</URL>
        <Description>SUSE Bug 1172478</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2020-15469</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-15469.html</URL>
        <Description>CVE-2020-15469</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1173612</URL>
        <Description>SUSE Bug 1173612</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked.</Note>
    </Notes>
    <CVE>CVE-2020-25084</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25084.html</URL>
        <Description>CVE-2020-25084</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1176673</URL>
        <Description>SUSE Bug 1176673</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.</Note>
    </Notes>
    <CVE>CVE-2020-25624</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.4</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25624.html</URL>
        <Description>CVE-2020-25624</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1176682</URL>
        <Description>SUSE Bug 1176682</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop.</Note>
    </Notes>
    <CVE>CVE-2020-25625</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25625.html</URL>
        <Description>CVE-2020-25625</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1176684</URL>
        <Description>SUSE Bug 1176684</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host, resulting in a denial of service.</Note>
    </Notes>
    <CVE>CVE-2020-25723</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-25723.html</URL>
        <Description>CVE-2020-25723</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178934</URL>
        <Description>SUSE Bug 1178934</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178935</URL>
        <Description>SUSE Bug 1178935</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">eth_get_gso_type in net/eth.c in QEMU 4.2.1 allows guest OS users to trigger an assertion failure. A guest can crash the QEMU process via packet data that lacks a valid Layer 3 protocol.</Note>
    </Notes>
    <CVE>CVE-2020-27617</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-27617.html</URL>
        <Description>CVE-2020-27617</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178174</URL>
        <Description>SUSE Bug 1178174</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host, resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.</Note>
    </Notes>
    <CVE>CVE-2020-27821</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-27821.html</URL>
        <Description>CVE-2020-27821</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179686</URL>
        <Description>SUSE Bug 1179686</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.</Note>
    </Notes>
    <CVE>CVE-2020-28916</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-28916.html</URL>
        <Description>CVE-2020-28916</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178683</URL>
        <Description>SUSE Bug 1178683</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179468</URL>
        <Description>SUSE Bug 1179468</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.</Note>
    </Notes>
    <CVE>CVE-2020-29129</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29129.html</URL>
        <Description>CVE-2020-29129</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179466</URL>
        <Description>SUSE Bug 1179466</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179467</URL>
        <Description>SUSE Bug 1179467</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179477</URL>
        <Description>SUSE Bug 1179477</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179484</URL>
        <Description>SUSE Bug 1179484</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.</Note>
    </Notes>
    <CVE>CVE-2020-29130</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29130.html</URL>
        <Description>CVE-2020-29130</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179467</URL>
        <Description>SUSE Bug 1179467</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1179477</URL>
        <Description>SUSE Bug 1179477</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.</Note>
    </Notes>
    <CVE>CVE-2020-29443</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.3</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29443.html</URL>
        <Description>CVE-2020-29443</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181108</URL>
        <Description>SUSE Bug 1181108</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20181</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20181.html</URL>
        <Description>CVE-2021-20181</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182137</URL>
        <Description>SUSE Bug 1182137</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.</Note>
    </Notes>
    <CVE>CVE-2021-20203</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20203.html</URL>
        <Description>CVE-2021-20203</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181639</URL>
        <Description>SUSE Bug 1181639</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields and their subsequent processing. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.</Note>
    </Notes>
    <CVE>CVE-2021-20221</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20221.html</URL>
        <Description>CVE-2021-20221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1181933</URL>
        <Description>SUSE Bug 1181933</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.</Note>
    </Notes>
    <CVE>CVE-2021-20257</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-20257.html</URL>
        <Description>CVE-2021-20257</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182577</URL>
        <Description>SUSE Bug 1182577</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182846</URL>
        <Description>SUSE Bug 1182846</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.</Note>
    </Notes>
    <CVE>CVE-2021-3416</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-arm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-alsa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-oss-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-pa-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-audio-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-curl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-iscsi-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-rbd-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-block-ssh-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-guest-agent-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ipxe-1.0.0+-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-kvm-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-lang-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ppc-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-s390-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-seabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-sgabios-8-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-tools-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-curses-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-gtk-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-ui-sdl-3.1.1.1-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-vgabios-1.12.0_0_ga698c89-48.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:qemu-x86-3.1.1.1-48.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2021/suse-su-20211242-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3416.html</URL>
        <Description>CVE-2021-3416</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1182968</URL>
        <Description>SUSE Bug 1182968</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186473</URL>
        <Description>SUSE Bug 1186473</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
