[Secure-testing-commits] r29750 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Fri Oct 31 05:09:00 UTC 2014


Author: carnil
Date: 2014-10-31 05:09:00 +0000 (Fri, 31 Oct 2014)
New Revision: 29750

Modified:
   data/CVE/list
Log:
Update information for CVE-2014-3689/qemu

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2014-10-31 05:08:50 UTC (rev 29749)
+++ data/CVE/list	2014-10-31 05:09:00 UTC (rev 29750)
@@ -11163,7 +11163,8 @@
 	- qemu <unfixed> (bug #765496)
 	- qemu-kvm <removed>
 	[squeeze] - qemu-kvm <end-of-life>
-	TODO: check
+	NOTE: Upstream's quick and easy stopgap for this issue: compile out the hardware acceleration functions which lack sanity checks.
+	NOTE: http://git.qemu.org/?p=qemu.git;a=commitdiff;h=83afa38eb20ca27e30683edc7729880e091387fc
 CVE-2014-3688 [net: sctp: remote memory pressure from excessive queueing]
 	RESERVED
 	- linux <unfixed>




More information about the Secure-testing-commits mailing list