qemu 1:4.0+dfsg-0ubuntu11 source package in Ubuntu


qemu (1:4.0+dfsg-0ubuntu11) focal; urgency=medium

  * SECURITY UPDATE: infinite loop when executing LSI scsi adapter
    emulator scripts
    - d/p/u/CVE-2019-12068.patch: Move the existing loop exit
    - CVE-2019-12068
  * SECURITY UPDATE: null pointer dereference in qxl display driver
    - d/p/u/CVE-2019-12155.patch: qxl: check release info object
    - CVE-2019-12155
  * SECURITY UPDATE: qemu-bridge-helper interface name buffer overflow
    - d/p/u/CVE-2019-13164.patch: qemu-bridge-helper: restrict
      interface name to IFNAMSIZ
    - CVE-2019-13164
  * SECURITY UPDATE: heap overflow in slirp
    - d/p/u/CVE-2019-14378.patch: slirp: Fix heap overflow in ip_reass
      on big packet input
    - CVE-2019-14378
  * SECURITY UPDATE: use after free vulnerability in slirp
    - d/p/u/CVE-2019-15890.patch: slirp: ip_reass: Fix use after free
    - CVE-2019-15890
  * Add support for exposing "taa-no" flag to guests:
    - d/p/u/CVE-2019-11135-taa-no.patch
    - CVE-2019-11135
  * Add support for exposing "pschange-mc-no" to guests:
    - d/p/u/pschange-mce.patch

 -- Steve Beattie <email address hidden>  Thu, 07 Nov 2019 20:54:32 -0800

Upload details

Uploaded by:
Steve Beattie on 2020-01-17
Sponsored by:
Marc Deslauriers
Uploaded to:
Original maintainer:
Ubuntu Developers
any all
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section


File Size SHA-256 Checksum
qemu_4.0+dfsg.orig.tar.xz 30.7 MiB 9802e0c920eb6c87371b13864005b51aa8dda288e9667fb80d6b1fa7d185b6d9
qemu_4.0+dfsg-0ubuntu11.debian.tar.xz 194.5 KiB ea72a3c62c35d56629f701cbd0d7d84ead11fea01b94910d56ecc874b36247db
qemu_4.0+dfsg-0ubuntu11.dsc 6.6 KiB 668e7a2a05982aed00fcd759bf564c4d1babed3da135107a05a923886c360b60

View changes file

Binary packages built by this source