[Git][security-tracker-team/security-tracker][master] Track fixed version for various qemu issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 20:35:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b8bc1d76 by Salvatore Bonaccorso at 2026-07-26T21:34:38+02:00
Track fixed version for various qemu issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15,37 +15,37 @@ CVE-2026-17458 (A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. Th
 CVE-2026-17457 (A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Aff ...)
 	TODO: check
 CVE-2026-63319
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3995
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1e54185745ba896af2beb5259b61ba6473e9881e (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6970b91d905f72ba952c4d224ab8d6192ef9b39d (v10.0.12)
 CVE-2026-61475
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3935
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/24767bcf0fdcd19415cb07c06f637ea29a5cebbb (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6c2f9592dec667796dacdffd7adbd065948fe212 (v10.0.12)
 CVE-2026-16043
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4001
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/2a5bc4de0f544a3739c32a99b11a9e78e71472c2 (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/b0411a1747ac9b205633011f62ac85436f354f35 (v10.0.12)
 CVE-2026-15705
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/b2d1fe67d09d2b6c7da647fbcea6ca0148c206d3 (v1.4.0-rc0)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6229fbcef1f878b2df081c7911c7eaae12e54da5 (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e3da91c85971de1d5a31f5f2a5b0f6ef34a4e8a7 (v10.0.12)
 CVE-2026-15578
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: https://gitlab.com/qemu-project/qemu/-/issues/3976
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/147e214e9cbd701c0569193004800c4f75bf9575 (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/7467c162c0b19a0ac1822172e131d34943ca54ad (v10.0.12)
 CVE-2026-8348 [hw/9pfs: add xattr FID limit to prevent memory exhaustion]
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/10b468bdc5335b58f610817215f30847c1429f24 (v0.14.0-rc0)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/c57644a542b11e578309b07b3bf7623d566e6a81 (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4f9e9601d0ec69748b2019a34dde148578b2c5a4 (v10.0.12)
 CVE-2026-9238 [hw/9pfs: cap Treaddir allocation]
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/2149675b195f2d9a1a4e3b966d45aba234def69b (v5.2.0-rc0)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d2a298f359477fd6fa30dd6aa7357115b596012d (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/169537e616a894175cd7c876c83b4801fe099232 (v10.0.12)
@@ -24710,7 +24710,7 @@ CVE-2026-10643 (Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sock
 CVE-2026-10593 (The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-48002
-	- qemu <unfixed>
+	- qemu 1:11.0.3+ds-1
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/00589953cc263ed8098fa9c0a007a9b04d470f85 (v11.0.2)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/52155a6affd077f7e50fd0aca99a391d6e9e7066 (v11.0.2)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/738927b263c7dcd14edff148826b28990b18ae46 (v11.0.3)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8bc1d76a55368f52baae251baee0c69ae495e2b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b8bc1d76a55368f52baae251baee0c69ae495e2b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/7218cf47/attachment.htm>


More information about the debian-security-tracker-commits mailing list