security advisorycritical issuesoftware update It was found that the patch for CVE-2021-3592 introduced a regression which prevented ssh connections to the host system. Since there is no imminent solution for the problem, the patch for CVE-2021-3592 has been reverted. Updated qemu packages are now available to correct this issue. . -------------------------------------------------------------------------Debian LTS Advisory DLA-2753-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany September 11, 2021 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : qemu Version : 1:2.8+dfsg-6+deb9u16 CVE ID : CVE-2021-3592 Debian Bug : 994080 It was found that the patch for CVE-2021-3592 introduced a regression which prevented ssh connections to the host system. Since there is no imminent solution for the problem, the patch for CVE-2021-3592 has been reverted. Updated qemu packages are now available to correct this issue. For Debian 9 stretch, this problem has been fixed in version 1:2.8+dfsg-6+deb9u16. We recommend that you upgrade your qemu packages. For the detailed security status of qemu please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/qemu Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Notification regarding a qemu bug impacting ssh connectivity. New package updates released to fix the issues.. Debian LTS, Qemu Update, Security Patch, Regression Issues. . Severity: Critical. LinuxSecurity.com Team
Sep 11, 2021 •Critical Debian LTS