[ubuntu/cosmic-security] qemu 1:2.12+dfsg-3ubuntu8.7 (Accepted)

Steve Beattie sbeattie at ubuntu.com
Tue May 14 17:03:34 UTC 2019


qemu (1:2.12+dfsg-3ubuntu8.7) cosmic-security; urgency=medium

  * SECURITY UPDATE: Add support for exposing md-clear functionality
    to guests
    - d/p/ubuntu/enable-md-clear.patch
    - CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091
  * SECURITY UPDATE: heap overflow when loading device tree blob
    - d/p/ubuntu/CVE-2018-20815.patch: specify how large the buffer to
      copy the device tree blob into is.
    - CVE-2018-20815
  * SECURITY UPDATE: device driver denial of service via NULL pointer
    dereference
    - d/p/ubuntu/CVE-2019-5008.patch: Define skeleton 'power_mem_read'
      routine
    - CVE-2019-5008
  * SECURITY UPDATE: information leak in SLiRP
    - d/p/ubuntu/CVE-2019-9824.patch: check sscanf result when
      emulating ident.
    - CVE-2019-9824

Date: 2019-05-10 18:06:13.102948+00:00
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
https://launchpad.net/ubuntu/+source/qemu/1:2.12+dfsg-3ubuntu8.7
-------------- next part --------------
Sorry, changesfile not available.


More information about the Cosmic-changes mailing list