#1085299 qemu: CVE-2024-6519

Package:
src:qemu
Source:
src:qemu
Submitter:
Moritz Mühlenhoff
Date:
2026-05-13 05:59:03 UTC
Severity:
normal
Tags:
#1085299#5
Date:
2024-10-17 21:06:16 UTC
From:
To:
Hi,

The following vulnerability was published for qemu.

CVE-2024-6519[0]:
qemu: SCSI: lsi53c895a: use-after-free local privilege escalation vulnerability

https://bugzilla.redhat.com/show_bug.cgi?id=2292089

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-6519
https://www.cve.org/CVERecord?id=CVE-2024-6519

Please adjust the affected versions in the BTS as needed.

#1085299#22
Date:
2026-05-13 04:45:25 UTC
From:
To:
This has been fixed in upstream version 11.0.0, with commit
https://gitlab.com/qemu-project/qemu/-/commit/4862d2c95104d9fd0430cc003c205094f8ada1f9
,
which is also being picked-up for older qemu stable releases.
https://gitlab.com/qemu-project/qemu/-/issues/3090

Thanks,

/mjt