[ubuntu/bionic-security] qemu 1:2.11+dfsg-1ubuntu7.35 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Feb 8 12:57:25 UTC 2021


qemu (1:2.11+dfsg-1ubuntu7.35) bionic-security; urgency=medium

  * SECURITY UPDATE: heap overread in iscsi_aio_ioctl_cb
    - debian/patches/CVE-2020-11947.patch: fix heap-buffer-overflow in
      block/iscsi.c.
    - CVE-2020-11947
  * SECURITY UPDATE: use-after-free in e1000e
    - debian/patches/CVE-2020-15859.patch: forbid the reentrant RX in
      net/queue.c.
    - CVE-2020-15859
  * SECURITY UPDATE: infinite loop in e1000e
    - debian/patches/CVE-2020-28916.patch: advance desc_offset in case of
      null descriptor in hw/net/e1000e_core.c.
    - CVE-2020-28916
  * SECURITY UPDATE: out of bounds read in atapi
    - debian/patches/CVE-2020-29443-1.patch: assert that the buffer pointer
      is in range in hw/ide/atapi.c.
    - debian/patches/CVE-2020-29443-2.patch: check logical block address
      and read size in hw/ide/atapi.c.
    - CVE-2020-29443
  * SECURITY UPDATE: use after free in 9p
    - debian/patches/CVE-2021-20181.patch: fully restart unreclaim loop in
      hw/9pfs/9p.c.
    - CVE-2021-20181

Date: 2021-02-04 13:55:16.271630+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.35
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list