• [SECURITY] [DSA 4454-1] qemu security update

    From Moritz Muehlenhoff@1:229/2 to All on Thu May 30 20:10:01 2019
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4454-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    May 30, 2019 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : qemu
    CVE ID : CVE-2018-11806 CVE-2018-12617 CVE-2018-16872 CVE-2018-17958
    CVE-2018-18849 CVE-2018-18954 CVE-2018-19364 CVE-2018-19489
    CVE-2019-3812 CVE-2019-6778 CVE-2019-9824 CVE-2019-12155

    Multiple security issues were discovered in QEMU, a fast processor
    emulator, which could result in denial of service, the execution of
    arbitrary code or information disclosure.

    In addition this update backports support to passthrough the new
    md-clear CPU flag added in the intel-microcode update shipped in DSA 4447
    to x86-based guests.

    For the stable distribution (stretch), these problems have been fixed in version 1:2.8+dfsg-6+deb9u6.

    We recommend that you upgrade your qemu packages.

    For the detailed security status of qemu please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/qemu

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlzwG0wACgkQEMKTtsN8 TjaUfBAAjsUcRK6UZzATOVxB2bm5sTN3FzD9G1ek4vytU9dPhJFWB+jhCP6kuEVU VzuhNEOKmf1J0OxxjXQyF1rgDAJe+WmvcV++u4f/2Zz4H5Q1muWUYaSK0o3476GK ld3VOU8+Jp+CDvfFAauMoM4a/Pd10YcfRsCcLDKaPb+mdtDMtyplxnbtoUNPuNEQ OdVFzWj8VmyryfwS98cPml7d97EkjT4ujqxHhOQ+4xYWAmhsYCCeP7ycqa/UH1ef gUxGNp51Gg3quP4B71bYsLYIMaL5SLYSM22Agy343SzmTwjdVx/MrGwI86zXvbtC vRk4oIvxCoEXPsZ8DZTnns5VwSf3JeWVzLlRWwkikjwREV3NFPLEtOhDGtaHZ4sZ uQiEn1HmvM6aVk7Hk0oxXaVkPKeZ3PmjaT9bf5mruIFpVwALJjmuCR8r4NOcSLIi S6Lpb8wg8YT3FQUKnimnK1bTP9qxdviZxBVNAa7gsiSUA4xoa2IY+Xw8Jc6+XMpE VAS1Lz1CII4lSi2JlqesiXBo1Qp9RuNMNUIdPdy0T2l2JBfd0hPXvKB867uFWgyg TRHI4ly/r9SCmrmioTmF1HsvwRIP9JCH8uIDp73OFIK6hCK9FJo9U4BcZoYQTU7V WnDTdtTv9zEQVW59EevBB+57mKFkRNTJHRignQrbGBgk11qRhqE=
    =btZi
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)