Bug 53791 - qemu: Multiple issues (4.4)
qemu: Multiple issues (4.4)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.4
All Linux
: P3 normal (vote)
: UCS 4.4-8-errata
Assigned To: Quality Assurance
Philipp Hahn
:
Depends on:
Blocks: 53777
  Show dependency treegraph
 
Reported: 2021-09-15 16:46 CEST by Philipp Hahn
Modified: 2021-09-18 17:59 CEST (History)
0 users

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score: 3.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Philipp Hahn univentionstaff 2021-09-15 16:46:44 CEST
New Debian qemu 1:2.8+dfsg-6+deb9u16A~4.4.8.202109130906 fixes:
This update addresses fixes a regression in erratum 1044:
* Revert patch for CVE-2021-3592: It was found that the patch for CVE-2021-3592 introduced a regression which prevented ssh connections to the host system.
Comment 1 Quality Assurance univentionstaff 2021-09-15 16:49:09 CEST
--- mirror/ftp/4.4/unmaintained/component/4.4-8-errata/source/qemu_2.8+dfsg-6+deb9u15A~4.4.8.202109060928.dsc
+++ apt/ucs_4.4-0-errata4.4-8/source/qemu_2.8+dfsg-6+deb9u16A~4.4.8.202109130906.dsc
@@ -1,4 +1,4 @@
-1:2.8+dfsg-6+deb9u15A~4.4.8.202109060928 [Mon, 06 Sep 2021 09:35:39 +0200] Univention builddaemon <buildd@univention.de>:
+1:2.8+dfsg-6+deb9u16A~4.4.8.202109130906 [Mon, 13 Sep 2021 09:14:33 +0200] Univention builddaemon <buildd@univention.de>:
 
   * UCS auto build. The following patches have been applied to the original source package
     0001-Disable-Xen-for-UCS
@@ -13,9 +13,16 @@
     1007-0008-x86-Work-around-SMI-migration-breakages
     1008-0009-migration-ram.c-do-not-set-postcopy_running-in-POSTC
 
+1:2.8+dfsg-6+deb9u16 [Sat, 11 Sep 2021 18:47:27 +0200] Markus Koschany <apo@debian.org>:
+
+  * Non-maintainer upload by the LTS team.
+  * Revert patch for CVE-2021-3592:
+    It was found that the patch for CVE-2021-3592 introduced a regression which
+    prevented ssh connections to the host system. (Closes: #994080)
+
 1:2.8+dfsg-6+deb9u15 [Wed, 01 Sep 2021 23:08:52 +0200] Markus Koschany <apo@debian.org>:
 
-  * Non-maintainer upload by the ELTS team.
+  * Non-maintainer upload by the LTS team.
   * Fix CVE-2021-3713:
     An out-of-bounds write flaw was found in the UAS (USB Attached SCSI) device
     emulation of QEMU. The device uses the guest supplied stream number

<http://piuparts.knut.univention.de/4.4-8/#698585350022217283>
Comment 2 Philipp Hahn univentionstaff 2021-09-15 17:25:03 CEST
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[4.4-8] 4a496a3f59 Bug #53791: qemu_1:2.8+dfsg-6+deb9u16A~4.4.8.202109130906
 doc/errata/staging/qemu.yaml | 14 ++++++++++++++
 1 file changed, 14 insertions(+)