ChangeLog/11.1
Release schedule: Planning/11.1.
System emulation
Removed features and incompatible changes
New deprecated options and features
- The low level `-mon` argument is obsoleted by the new `-object` support with 'monitor-qmp' and 'monitor-hmp' types.
Guest CPUs
68k
Alpha
Arm
- The virt board now allows users to specify the cache topology for virtual machines.
- New machine type: imx8mp-evk models the i.MX 8MM EVK(Evaluation Kit) board
- qemu-system-aarch64 now allows you to boot a 32-bit guest on a 64-bit TCG CPU with "-cpu <type>,aarch64=off"
- fsl-imx6ul: The LCDIF display device is now implemented
- hvf: now supports the platform vGIC for the virt board
- hvf: support nested virtualization for the virt board
- There is now an experimental emulation of the GICv5 interrupt controller. Consult the documentation of the "gic-version=x-5" option in docs/system/arm/virt.rst for more information and details of what its experimental status means.
- On NVIDIA Tegra241 hardware, Command Queue Virtualisation (CMDQV) support is now available via "-device arm-smmuv3,accel=on,cmdqv=on", giving each VM dedicated hardware SMMUv3 command queues, improving performance.
- The sabrelite board now supports FlexCAN emulation
- Arm boards now support loading the UEFI shim via the standard '-shim' argument
- WFE and WFET are now implemented to no longer be mere no-ops, including honouring trap conditions
- WFIT/WFET properly report syndrome and register information
- New CPU architectural features emulated:
- FEAT_FAMINMAX
- FEAT_FPMR
- FEAT_CMPBR
- FEAT_RNG_TRAP
- FEAT_F8F16MM
- FEAT_F8F32MM
- FEAT_FP8DOT2
- FEAT_SSVE_FP8DOT2
- FEAT_FP8DOT4
- FEAT_SSVE_FP8DOT4,
- FEAT_FP8FMA
- FEAT_SSVE_FP8FMA
- FEAT_SME_LUTv2
- FEAT_SME_F8F32
- FEAT_SME_F8F16
- FEAT_SSVE_AES
- FEAT_FP8
- FEAT_LUT
- FEAT_MTE_CANONICAL_TAGS,
- FEAT_MTE_NO_ADDRESS_TAGS
- FEAT_MTE_PERM
- FEAT_MTE_STORE_ONLY
- FEAT_MTE_TAGGED_FAR
- FEAT_MTE4
- FEAT_RME_GPC3
- FEAT_SME_MOP4
- FEAT_FPRCVT
- FEAT_SSVE_FEXPA
- FEAT_WxFT
AVR
Hexagon
- The initial system emulation support is now present. But until semihosting and interrupt controller features arrive, the uses for hexagon system emulation are very limited in 11.1. Consider using a subsequent release when available.
- Fixed unaligned accesses for linux-user emulation. Note well: this means that defective programs which appeared to behave normally will now start to (correctly) generate a bus error when performing an unaligned scalar access.
HPPA
- New firmware SeaBIOS-hppa v25
- Fast TLB insert fix for HP-UX 9
LoongArch
Microblaze
MIPS
OpenRISC
PowerPC
- MPIPL support for PowerNV
- ppc/spapr: Make Power11 as default cpu for pseries
- ppc/pnv: Make PowerNV11 as the default powernv machine
- SLOF FW update to 20260627
- Testcase improvements for PowerNV
- Removal of deprecated Power8E and 8NVL CPUs
- ppc/pnv: Add a nest MMU model
- hw/ssi/pnv_spi: Fix fifo8 memory leak on unrealize
- hw/intc/xics: Add a check for an invalid server id
- ppc/spapr: skip system reset for quiesced CPUs
- ppc/pnv: Fix uninitialized MpiplProcDumpArea struct
- target/ppc/kvm: Fix const violation when trimming CPU alias suffix
- ppc/pnv: external dtb fix and test addition
- PHB code refactor for better maintainability
- Revert deprecation of 405 CPUs
- target/ppc: Expose TB offset of guest in Qemu monitor
Renesas RX
Renesas SH (sh4)
- Signal handler and libunwind fixes for linux-user
- decode_gusa: recognize add#imm with prior mov Rm, Rn
RISC-V
ISA and Extensions
- Add RISC-V big-endian target support
- Add draft RISC-V Zbr ext as xbr0p93
- Add Zvfbfa extension support
- Allow fractional LMUL on vector SHA instructions
- Add KVM support for Zicbop and BFloat16 extensions
- Add 'cbo' insns to disassembler
- Enable `mnret` disassembly
- Do not hide Sstc CSRs from gdbstub
- Reject Svinval instructions in U-mode
- Fault with reserved PTE.PBMT val
- Allow LOAD_ADDR_MIS promotion to AMO fault
- Add PMA access fault
Machines
- Remove spike as default machine
- Deprecate the shakti_c machine
- Add Tenstorrent mvendorid
- Update OpenSBI to v1.8.1
- Implement Microchip mpfs ioscb PLLs and sysreg clock dividers
- Add support for K230 board
- Fix --disable-tcg builds
Fixes and Misc
- Fix irq_overflow_left residual value bug in IOMMU
- Add IPSR.PMIP RW1C support to IOMMU
- Use kvm timer frequency when kvm enabled
- Fix stale ptshift and base on page walk restart
- Fix heap OOB in ACLINT MTIMER multi-socket
- Reject RISC-V HTIF invalid signature ranges
- Fix RV32 henvcfg/stateen CSR handling
- Mask xepc[0] only when Zc* extension is enabled
- Generate access fault if sc comparison fails
- Don't OR mip.SEIP when mvien is one
- Use ELEN for Fractional LMUL check
- Fix Zjpm implementation
- Handle mask/source overlap of vector reduction instructions
- Fix Svnapot 64KB pages
- Set MISA.[C|X] based on the selected extensions
- Handle source overlap of vector widening reduction instructions
- Check interrupt in SiFive UART after txctrl register is written
- Fix medeleg[11] read-only zero bit for M-mode ECALL
- Fix tail handling for vmv.s.x and vfmv.s.f
- Update the local AIA interrupt mask
- Fix the IOMMU FSC SV32 capability check
- Fix the read of pmpaddr(0-63) CSRs
- Make hpmcounterh return the upper 32-bits
- Re-process IOMMU command queue after clearing CMD_ILL
- Disable svpbmt if satp_mode is less then sv39
- Disable svnapot if satp_mode is less then sv39
- Numerous IOMMU fixes and compliance updates
- Check PCIe DOE mailbox length for overflows
- Add extensions after v7.1-rc4 update
- Correct ACPI field sequence in SPCR table
- Fix RISC-V privilege level in uftrace plugin
s390x
- kvm: add support for the ASTFLE facility 2 (for nested)
- enable boot menu for virtio-pci devices
- disable legacy virtio-pci devices, which had never worked in the first place
- Fixes:
- assorted hardening fixes for the guest->host interface
- fix some intermittent errors when booting from virtio-pci devices
- various other fixes all over the place
SPARC
Tricore
x86
Xtensa
Accelerators
KVM
TCG
- Fixed an issue with TB invalidation on MacOS [1]
Xen
Other accelerators
Device emulation and assignment
9pfs
- Fix read-only bypass via O_TRUNC on read-only exports (CVE-2026-63318, commit a0414545).
- Fix potential host memory exhaustion by limiting the number of simultaneously open xattr fids to 1024 by default (CVE-2026-8348, commit 693b296b17), this limit can be overridden by the newly introduced option max_xattr (commit e6116a81f0, docs 44cb540d2d).
- Fix V9fsPath heap buffer overflow (bug #3358, commit 3802c0e7).
- Fix missing rename lock in v9fs_co_readdir_many (CVE-2026-48004, commit 5a8da7e9).
- Fix abort (DoS) due to illegal name with legacy Twstat rename request (commit 7f5445e7).
- Fix DoS via Treaddir (CVE-2026-9238, commit 64c6c7e0df).
- Fix union V9fsFidOpenState type confusion (commit 32cae47c33).
- virtio: Fix potential UAF via guest-triggered ACPI eject (commit 210701c8).
- Xen: Fix potential UAF after disconnect (commit 1de8aea0).
ACPI / SMBIOS
Audio
Block devices
Graphics
- vga: implement blinking in text mode
I2C
Input devices
IPMI
Network devices
NVDIMM
NVMe
PCI/PCIe
SCSI
SD card
SMBIOS
TPM
UFS
- Added support for UFS Write Booster emulation based on the UFS 4.1 specification.
- Added support for Host Initiated Defragmentation (HID) emulation based on the UFS 4.1 specification.
USB
- Fixed possible use-after-free problem in "usb-redir" device (CVE-2026-15705)
- Fixed possible infinite loop or crash in "usb-redir" device (CVE-2026-63319)
- Fixed possible out-of-bounds heap access in XHCI sysbus device, e.g. used on the "microvm" machine (CVE-2026-16043)
VFIO
virtio
- use-after-free fix for virtio-gpu (CVE-2026-6502)
- fix crash when now EGL available on Windows
- add vhost-user-rtc device to connect to vhost-user daemons offering a virtio-rtc implementation
vDPA
Other QEMU sub-systems
Audio
Authorization subsystem
Block subsystem
Character devices
Crypto subsystem
- Fix creation of anonymous TLS credentials (tls-creds-anon object)
- The --enable-nettle / --enable-gcrypt configure flags are now correctly honoured again.
Dump
- prevent dumping from migrating VMs
- make win-dmp available only when Windows has published vmcoreinfo dump header
- new dump-guest-memory test
GDBStub
GUI
- vc chardevs now have "encoding" option to specify the expected character set (cp437 or utf8)
- -display dbus now exposes org.qemu.Display1.Chardev.VCEncoding
- the vt100 emulator now supports utf8 encoding with CP437 rendering
- new "qemu-vnc" standalone VNC server, to export -display dbus
- -display gtk: better handling of console hotplugging
- improve resource cleanups on exit
fw_cfg
I/O subsystem
Memory backends
- Fixed virtio-mem behavior within CoCo VMs (still needs guest OS support)
Migration
- CPR-transfer downtime optimization for FD lookups using hash table\
- A new parameter x-rdma-chunk-size is added for RDMA migration to specify chunk size
- Enhanced query-migrate results with both system-wide remaining bytes reporting and expected downtime calculations (to include VFIO device states)
- Fixed a regression on migrate-set-parameters crashing QEMU when both multifd and zerocopy are enabled
- Fixed a possible migration hang in POSTCOY_DEVICE state when dest QEMU failed to ACK
- Fixed a possible crash on a second migration if the first migration got cancelled before channel establishment
- Fixed a possible but rare crash in VFIO migration
Monitor
QMP
- The QMP monitor can now be created with '-object monitor-qmp,id=NNN,chardev=MMM', with '-mon' deprecated. The high level '-qmp' syntactic sugar remains unchanged.
- It is now possible to hot-add and hot-remove QMP monitor instances using the `object-add` command and new 'monitor-qmp' type
- The QMP monitor can be set to automatically delete when the client closes the connection via the new "close-action=delete" parameter.
HMP
- The HMP monitor can now be created with '-object monitor-hmp,id=NNN,chardev=MMM', with '-mon' deprecated. The high level '-monitor' syntactic sugar remains unchanged.
- It is now possible to hot-add (but NOT hot-remove) HMP monitor instances using the `object-add` command and new 'monitor-hmp' type
Network
Record/Replay
Semihosting
TCG Plugins
- Refactored API to ensure all callbacks can receive userdata. This removes the need to have global variables to maintain state.
Tracing
User-mode emulation
- Add emulation for preadv2() and pwritev2() syscalls
- Implement fsmount series of syscalls for systemd support
- Add emulation of /proc/cpuinfo file for ppc, loongarch and m68k CPUs
- Implement finer grained madivse() syscall
- VDSO support for sh4 and sh4eb
- Flush error messages at exit
- Fix IP multicast groups with different endian between host & guest
- Fix CLONE_PARENT_SETTID when using fork-style clone()
- Fix getifaddrs() on big-endian targets
- Fix strace addresses in read() and write() on riscv64
- Fix getsockopt() for SO_RCVTIMEO_NEW & SO_SNDTIMEO_NEW
- Fix signals/rt_sigframe stack offset for ppc32
- Signal handler fixes for sparc and sparc64
- Fix stat64 struct on loongarch64 guest
- Fixes for Cavium Octeon userspace
- Improved CDROM support (added ioctls)
- Allow getsockopt() with NULL optval address
- Translate errno in IP_RECVERR and IPV6_RECVERR
- Fix AT_EXECFN in AUXV for symlinked programs
- Fix AT_PHDR when program headers are relocated into their own segment
- Added coredump support and related fixes for hppa, riscv, alpha, sparc, mips64 and mipsn32
- Signal handler and libunwind fixes for sh4 target
- Various fixes in handling of floating point registers during signal delivery for ppc, mips, sh4, xtensa and s390x
- Fix unlock of uninitialized frame pointer on sigreturn on xtensa
- Validate guest-passed dm_ioctl data_size
- Alpha: Fix programs using getauxval(AT_HWCAP) to detect BWX/FIX/CIX
- Allow full 32-bit address space for sh4 guest
- Fix msgctl syscall by correcting time and pid entries of the msqid_ds struct
- Fix token in map_shadow_stack syscall on aarch64
Tools and other binaries
Block tools
Guest agent
Documentation
Build Information
Dependencies
Host support
Rust usage
Testing and CI
- MacOS tests have been migrated from Cirrus to GitLab