XSA-346, XSA-457: A malicious domain with a PCI device (e.g., sys-net or
sys-usb in the default configuration) could try to exploit this
vulnerability in order to crash the host.

Just wanted to point out that there's a very minor typo here ('XSA-457').

Thank you for pointing out the typo. We'll make sure this gets fixed in the repo and website versions.

Also, since the last QSB was posted on Discourse, I was wondering if this
should be too.

It's automatic, but there might be a delay.

