[Git][security-tracker-team/security-tracker][master] Reserve DLA-3604-1 for qemu
Sean Whitton (@spwhitton)
spwhitton at debian.org
Thu Oct 5 16:53:38 BST 2023
Sean Whitton pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eb2addd9 by Sean Whitton at 2023-10-05T16:53:18+01:00
Reserve DLA-3604-1 for qemu
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -8878,7 +8878,6 @@ CVE-2023-3180 (A flaw was found in the QEMU virtual crypto device while handling
- qemu 1:8.0.4+dfsg-1
[bookworm] - qemu <no-dsa> (Minor issue)
[bullseye] - qemu <no-dsa> (Minor issue)
- [buster] - qemu <postponed> (Minor issue)
NOTE: Introduced by: https://gitlab.com/qemu-project/qemu/-/commit/04b9b37edda85964cca033a48dcc0298036782f2 (v2.8.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/9d38a8434721a6479fe03fb5afb150ca793d3980 (master)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/49f1e02bac166821c712534aaa775f50e1afe17f (v8.0.4)
@@ -42622,7 +42621,6 @@ CVE-2023-0330 (A vulnerability in the lsi53c895a device affects the latest versi
- qemu 1:8.0.2+dfsg-1 (bug #1029155)
[bookworm] - qemu 1:7.2+dfsg-7+deb12u1
[bullseye] - qemu <no-dsa> (Minor issue)
- [buster] - qemu <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2160151
NOTE: Proposed patch: https://lists.nongnu.org/archive/html/qemu-devel/2023-01/msg03411.html
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e49884a90987744ddb54b2fadc770633eb6a4d62 (v8.0.1)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[05 Oct 2023] DLA-3604-1 qemu - security update
+ {CVE-2020-24165 CVE-2023-0330 CVE-2023-3180}
+ [buster] - qemu 1:3.1+dfsg-8+deb10u11
[05 Oct 2023] DLA-3603-1 libxpm - security update
{CVE-2023-43786 CVE-2023-43787 CVE-2023-43788 CVE-2023-43789}
[buster] - libxpm 1:3.5.12-1+deb10u2
=====================================
data/dla-needed.txt
=====================================
@@ -157,10 +157,6 @@ python-os-brick
python3.7
NOTE: 20231003: Added by Front-Desk (Beuc)
--
-qemu (Sean Whitton)
- NOTE: 20230924: Added by Front-Desk (apo)
- NOTE: 20230924: Consider fixing postponed issues as well. (apo)
---
rails
NOTE: 20220909: Re-added due to regression (abhijith)
NOTE: 20220909: Regression on 2:5.2.2.1+dfsg-1+deb10u4 (abhijith)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb2addd983904718c33aeb2113278ee44f0f7740
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eb2addd983904718c33aeb2113278ee44f0f7740
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231005/9f1cfcac/attachment.htm>
More information about the debian-security-tracker-commits
mailing list