UbuntuUpdates.org

Package "qemu"

Name: qemu

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • supplemental block backend modules for qemu-system and qemu-utils
  • Guest-side qemu-system agent
  • QEMU full system emulation binaries (x86)
  • QEMU full system emulation (Xen helper package)

Latest version: 1:8.2.2+ds-0ubuntu1.2
Release: noble (24.04)
Level: updates
Repository: universe

Links



Other versions of "qemu" in Noble

Repository Area Version
base universe 1:8.2.2+ds-0ubuntu1
base main 1:8.2.2+ds-0ubuntu1
security main 1:8.2.2+ds-0ubuntu1.2
security universe 1:8.2.2+ds-0ubuntu1.2
updates main 1:8.2.2+ds-0ubuntu1.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1:8.2.2+ds-0ubuntu1.2 2024-08-22 08:07:04 UTC

  qemu (1:8.2.2+ds-0ubuntu1.2) noble-security; urgency=medium

  * SECURITY UPDATE: buffer overflow
    - debian/patches/CVE-2024-26327.patch: Check num_vfs size
    - CVE-2024-26327
  * SECURITY UPDATE: out of bounds memory access
    - debian/patches/CVE-2024-26328.patch: Use pcie_sriov_num_vfs to
      get number of enabled vfs before and after config writes
    - CVE-2024-26328

 -- Bruce Cable <email address hidden> Wed, 21 Aug 2024 11:53:08 +1000

CVE-2024-26327 An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater
CVE-2024-26328 An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interact



About   -   Send Feedback to @ubuntu_updates