Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-4454-1 Security Update for QEMU: Denial of Service Risks

debian
Calendar Grey May 30, 2019
Debian Logo
Numerous vulnerabilities discovered in recent QEMU release for Debian assessed against diverse risks. Ensure your software is updated.
Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or information disclosure

Summary

Multiple security issues were discovered in QEMU, a fast processor
emulator, which could result in denial of service, the execution of
arbitrary code or information disclosure.

In addition this update backports support to passthrough the new
md-clear CPU flag added in the intel-microcode update shipped in DSA 4447
to x86-based guests.

For the stable distribution (stretch), these problems have been fixed in
version 1:2.8+dfsg-6+deb9u6.

We recommend that you upgrade your qemu packages.

For the detailed security status of qemu please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/qemu

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: qemu
CVE ID: CVE-2018-11806 CVE-2018-12617 CVE-2018-16872 CVE-2018-17958

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here