[ubuntu/artful-security] qemu 1:2.10+dfsg-0ubuntu3.6 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed May 16 11:58:03 UTC 2018


qemu (1:2.10+dfsg-0ubuntu3.6) artful-security; urgency=medium

  * SECURITY UPDATE: arbitrary code execution via load_multiboot
    - debian/patches/CVE-2018-7550.patch: handle bss_end_addr being zero in
      hw/i386/multiboot.c.
    - CVE-2018-7550
  * SECURITY UPDATE: denial of service in Cirrus CLGD 54xx VGA
    - debian/patches/CVE-2018-7858.patch: fix region calculation in
      hw/display/vga.c.
    - CVE-2018-7858
  * debian/patches/vhost_fix_*.patch: restore avail index from vring used
    index on disconnection in hw/virtio/vhost.c.

Date: 2018-05-14 11:43:40.027741+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6
-------------- next part --------------
Sorry, changesfile not available.


More information about the Artful-changes mailing list