Format: 1.8 Date: Thu, 07 Nov 2019 22:48:19 -0800 Source: qemu Architecture: source Version: 1:3.1+dfsg-2ubuntu3.6 Distribution: disco-security Urgency: medium Maintainer: Ubuntu Developers Changed-By: Steve Beattie Changes: qemu (1:3.1+dfsg-2ubuntu3.6) disco-security; urgency=medium . * SECURITY UPDATE: infinite loop when executing LSI scsi adapter emulator scripts - d/p/u/CVE-2019-12068.patch: Move the existing loop exit - CVE-2019-12068 * SECURITY UPDATE: null pointer dereference in qxl display driver - d/p/u/CVE-2019-12155.patch: qxl: check release info object - CVE-2019-12155 * SECURITY UPDATE: qemu-bridge-helper interface name buffer overflow - d/p/u/CVE-2019-13164.patch: qemu-bridge-helper: restrict interface name to IFNAMSIZ - CVE-2019-13164 * SECURITY UPDATE: heap overflow in slirp - d/p/u/CVE-2019-14378.patch: slirp: Fix heap overflow in ip_reass on big packet input - CVE-2019-14378 * SECURITY UPDATE: use after free vulnerability in slirp - d/p/u/CVE-2019-15890.patch: slirp: ip_reass: Fix use after free - CVE-2019-15890 * Add support for exposing "taa-no" flag to guests: - d/p/u/CVE-2019-11135-taa-no.patch - CVE-2019-11135 * Add support for exposing "pschange-mc-no" to guests: - d/p/u/pschange-mce.patch Checksums-Sha1: 79c1f2bf0782894bae114a3c663510e8f484747c 6833 qemu_3.1+dfsg-2ubuntu3.6.dsc 18141dd99e320a8f08faea412ab7b8f06e07100a 228112 qemu_3.1+dfsg-2ubuntu3.6.debian.tar.xz a928afa8371b07b21a48b539a05e18e231dbacca 19513 qemu_3.1+dfsg-2ubuntu3.6_source.buildinfo Checksums-Sha256: 47692fee3d909ccb550f9167d193d0c0798cef02894f6d7fe07858a070b10994 6833 qemu_3.1+dfsg-2ubuntu3.6.dsc 032da50eebef18e353c0414be347be1a4f50bc7766c6be84250ff18facaacd8f 228112 qemu_3.1+dfsg-2ubuntu3.6.debian.tar.xz 407b1595869ad7d371500d3c91bd11ab4c510d104247162707595fba46b3f694 19513 qemu_3.1+dfsg-2ubuntu3.6_source.buildinfo Files: 071c06978db5d6180d05a239a1cbceb0 6833 otherosfs optional qemu_3.1+dfsg-2ubuntu3.6.dsc f3f9292f5136f8e689de18a9cc4cb8d5 228112 otherosfs optional qemu_3.1+dfsg-2ubuntu3.6.debian.tar.xz 0a6d1c1311658a9c646d78cecd5d9bda 19513 otherosfs optional qemu_3.1+dfsg-2ubuntu3.6_source.buildinfo Original-Maintainer: Debian QEMU Team