QEMU 11.1.0 is the security-bearing 11.1 release
Brief
The virtio-net CVE fix is already in this tarball.
Notes
Tag v11.1.0 is 84f07211cc5b. Announce: qemu-devel (Michael Roth, 2026-08-11). 11.1 ChangeLog. qemu.org post.
The ChangeLog is the source for the security list, not NVD. It names 9p, virtio-gpu, usb-redir, XHCI, s390x hardening, ACPI-eject virtio, and Xen disconnect items.
df12999cc813 says Fixes: CVE-2026-66022 and Resolves work_items/4073. It is on rc2, rc3, and the tag. The ChangeLog, the announce, and the qemu.org post do not name it. This is not an open hole in 11.1.0.
Unknown: whether every named CVE is fully backported to 11.0.x and 10.0.x. Stable 11.0.4 and 10.0.13 tags do not exist yet.
Commit 84f07211cc5b4fc6a371559bf8a5de4fb068e648 (tag v11.1.0); df12999cc81339ffb252875608919c72ccc37bcd (CVE-2026-66022, in that tag)