[Git][security-tracker-team/security-tracker][master] Add CVE-2025-12464/qemu

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Nov 1 07:36:06 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
90775db9 by Salvatore Bonaccorso at 2025-11-01T08:35:35+01:00
Add CVE-2025-12464/qemu

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,10 @@
+CVE-2025-12464 [Stack buffer overflow in e1000 device via short frames in loopback mode]
+	- qemu <unfixed>
+	[bookworm] - qemu <not-affected> (Vulnerable code introduced later)
+	[bullseye] - qemu <not-affected> (Vulnerable code introduced later)
+	NOTE: https://gitlab.com/qemu-project/qemu/-/issues/3043
+	NOTE: https://lore.kernel.org/qemu-devel/20251028160042.3321933-1-peter.maydell@linaro.org/T/#u
+	NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/140eae9c8f760e9260356fe9b56b802a02f0a9d2 (v8.1.0-rc0)
 CVE-2025-8849 (LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) att ...)
 	NOT-FOR-US: LibreChat
 CVE-2025-8489 (The King Addons for Elementor \u2013 Free Elements, Widgets, Templates ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90775db9d2f332325a5ebcca4ba0a9546d73a797

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/90775db9d2f332325a5ebcca4ba0a9546d73a797
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251101/bf88d9af/attachment.htm>


More information about the debian-security-tracker-commits mailing list