Univention Bugzilla – Bug 52001
qemu: Multiple issues (4.4)
Last modified: 2020-09-16 12:44:50 CEST
New Debian qemu 1:2.8+dfsg-6+deb9u11A~4.4.5.202009140857 fixes: This update addresses the following issues: * block: iscsi: OOB heap access via an unexpected response of iSCSI Server (CVE-2020-1711) * sd: OOB access could crash the guest resulting in DoS (CVE-2020-13253) * usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) * reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c (CVE-2020-16092)
--- mirror/ftp/4.4/unmaintained/component/4.4-5-errata/source/qemu_2.8+dfsg-6+deb9u10A~4.4.5.202007270634.dsc +++ apt/ucs_4.4-0-errata4.4-5/source/qemu_2.8+dfsg-6+deb9u11A~4.4.5.202009140857.dsc @@ -1,4 +1,4 @@ -1:2.8+dfsg-6+deb9u10A~4.4.5.202007270634 [Mon, 27 Jul 2020 06:37:26 +0200] Univention builddaemon <buildd@univention.de>: +1:2.8+dfsg-6+deb9u11A~4.4.5.202009140857 [Mon, 14 Sep 2020 09:01:24 +0200] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 0001-Disable-Xen-for-UCS @@ -13,6 +13,17 @@ 1007-0008-x86-Work-around-SMI-migration-breakages 1008-0009-migration-ram.c-do-not-set-postcopy_running-in-POSTC +1:2.8+dfsg-6+deb9u11 [Tue, 08 Sep 2020 12:54:35 +0530] Abhijith PA <abhijith@debian.org>: + + * Non-maintainer upload by the Debian LTS team. + * Fix CVE-2020-14364: out-of-bounds read/write access flaw + (Closes: #968947) + * Fix CVE-2020-13253: out-of-bounds read during sdhci_write() operations + (Closes: #961297) + * Fix CVE-2020-16092: assertion failure in net_tx_pkt_add_raw_fragment() + * Fix CVE-2020-1711: out-of-bounds heap buffer access flaw in iSCSI + Block driver (Closes: #949731) + 1:2.8+dfsg-6+deb9u10 [Sat, 25 Jul 2020 18:40:28 +0300] Michael Tokarev <mjt@tls.msk.ru>: * vnc-fix-memory-leak-when-vnc-disconnect-CVE-2019-20382.patch <http://10.200.17.11/4.4-5/#3389755353517303340>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-5] be70b75a7f Bug #52001: qemu 1:2.8+dfsg-6+deb9u11A~4.4.5.202009140857 doc/errata/staging/qemu.yaml | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x741>