-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 17 Mar 2021 21:02:30 +0300 Source: qemu Architecture: source Version: 1:5.2+dfsg-9 Distribution: unstable Urgency: medium Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org> Changed-By: Michael Tokarev <mjt@tls.msk.ru> Closes: 984448 984450 985040 985083 Changes: qemu (1:5.2+dfsg-9) unstable; urgency=medium . * do not make qemu-system-data dependent on qemu-system-foo (Closes: #985040) * CVE-2021-20263 - implement dropping security.capability xattr This adds two patches from upstream: virtiofsd-save-error-code-early-at-the-failure-callsite.patch virtiofsd-drop-remapped-security.capability-..-needed-CVE-2021-20263.patch Closes: #985083, CVE-2021-20263 * CVE-2021-3416 fix from upstream Fixes infinite loop in loopback mode of various network devices, adding 10 patches from upstream Closes: #984448, CVE-2021-3416 * net-e1000-fail-early-for-evil-descriptor-CVE-2021-20257.patch Fix CVE-2021-20257 from upstream: e1000: infinite loop while processing transmit descriptors Closes: #984450, CVE-2021-20257 Checksums-Sha1: 59a6c2e84500bbe27d625b83c844d5c47638f995 6600 qemu_5.2+dfsg-9.dsc 90ef3fa27ad9b1b1bb18ca7ae4d0e3131e445e70 108972 qemu_5.2+dfsg-9.debian.tar.xz a2d666b7fcca7c958af0abe5e10493e694e205ee 9086 qemu_5.2+dfsg-9_source.buildinfo Checksums-Sha256: 1029d93153038287290c1f19289855302e18a9b07cbcb3ce84dfa6387cccb951 6600 qemu_5.2+dfsg-9.dsc 86b159030760af80220c94bb62e0d26ef3866c61b02c337cf6cd855b66876b9c 108972 qemu_5.2+dfsg-9.debian.tar.xz f8285b8863e7884b1127e858e95ba747f3a625950e5e382d243c1dbf95038a5a 9086 qemu_5.2+dfsg-9_source.buildinfo Files: bf09363ce449bcfb6633d513a43d1830 6600 otherosfs optional qemu_5.2+dfsg-9.dsc a3676ebe1fa423ff5ae038874c81ee06 108972 otherosfs optional qemu_5.2+dfsg-9.debian.tar.xz 7aa9b852572ccbb160ad8ee2ec790602 9086 otherosfs optional qemu_5.2+dfsg-9_source.buildinfo -----BEGIN PGP SIGNATURE----- iQFDBAEBCAAtFiEEe3O61ovnosKJMUsicBtPaxppPlkFAmBSRXcPHG1qdEB0bHMu bXNrLnJ1AAoJEHAbT2saaT5ZSccH/i9K/l2QA1FbuEpMfo/nxbu3L0tkyqngpK3P 3hpTzJV6zEzA1YN5cyOXynU7qp9wah8R93Jp672ufigvGY37wA0r/lDjKN3XkCvl CkeLOQwbKAIMbbHyVRvQUMIo7/sK8fQmCkxlJrJBA7EfFM6QXWFZbxgp9HnJf0Wz lbFAGv3uStE5uU2M0aAsZdK5X8OUt6dBq5+KzJzjgzG505hqpxkWuxsyPAccjADN iNUFaMh43T/nuXC4dopqiqBTZY71L0aF0BCf99g3q0gcFktIS0622Fa30OJL5HKa eDu+Ifb1wtRcoWP1+iRXOCTbTc+ztdDwtQKjQGJFZ6mDozKUMNg= =FCJ8 -----END PGP SIGNATURE-----