[ubuntu/questing-updates] qemu 1:10.1.0+ds-5ubuntu2.6 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Thu Apr 9 19:20:32 UTC 2026
qemu (1:10.1.0+ds-5ubuntu2.6) questing-security; urgency=medium
* SECURITY UPDATE: use-after-free
- debian/patches/CVE-2024-6519.patch: keep a reference to the device while
SCRIPTS in hw/scsi/lsi53c895a.c.
- CVE-2024-6519
* SECURITY UPDATE: out-of-bounds read
- debian/patches/CVE-2026-2243.patch: fix OOB read in vmdk_read_extent()
in block/vmdk.c.
- CVE-2026-2243
* SECURITY UPDATE: heap buffer overflow
- debian/patches/CVE-2026-3195-1.patch: fix max_size bounds check in input
cb in hw/audio/virtio-snd.c.
- debian/patches/CVE-2026-3195-2.patch: tighten read amount in in_cb in
hw/audio/virtio-snd.c.
- CVE-2026-3195
* SECURITY UPDATE: integer overflow
- debian/patches/CVE-2026-3196.patch: handle 5.14.6.2 for PCM_INFO properly
in hw/audio/virtio-snd.c.
- CVE-2026-3196
* SECURITY UPDATE: out-of-bounds write
- debian/patches/CVE-2026-3842.patch: check length returned by
cpu_physical_memory_map() in hw/hyperv/syndbg.c.
- CVE-2026-3842
Date: 2026-04-01 20:25:50.936729+00:00
Changed-By: Fabian Toepfer <fabian.toepfer at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/qemu/1:10.1.0+ds-5ubuntu2.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list