On 7/26/26 19:20, Salvatore Bonaccorso wrote:
Hi Michael,
On Sun, Jul 26, 2026 at 04:42:22PM +0200, Salvatore Bonaccorso wrote:
Hi Michael,
On Sat, Jul 25, 2026 at 10:06:29AM +0300, Michael Tokarev wrote:
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:qemu
User: [email protected]
Usertags: pu
[ Reason ]
New upstream stable/bugfix release. With more than 120 fixes all
over the places, - fixing bugs, correctness. Including the following
CVE fixes:
CVE-2026-8348 CVE-2026-9238 CVE-2026-15578 CVE-2026-15705
CVE-2026-16043 CVE-2026-48002 CVE-2026-61475 CVE-2026-63319
Is this the correct set of CVEs for this round? I'm asking because
CVE-2026-48002 was already fixed with 1:10.0.11+ds-0+deb13u1 ?
Now this is interesting. I haven't noticed. There were 2 fixes for the
same CVE# in 2 different patches, both changing the same area (second one
adding stuff to the first), both titled the same way, and both claim to
fix the same CVE#.
First, which went into 10.0.11 and is already in debian:
https://gitlab.com/qemu-project/qemu/-/commit/46ee49034d26d04d95ba8f3183d4fbfa9d2b89b4
Second, which is this one in 10.0.12:
https://gitlab.com/qemu-project/qemu/-/commit/3543c2b855cc8cd25a5dbf05564a47ba42f45fad
It looks like it's actually the same issue, which is fixed in previous
version only partially, and is now being fixed for good.
Either way, it's definitely worth to mention previous fix in the
second one.
Okay that one consist of 3 commits, two of wich were in the earlier
release and the last one in v10.0.12 upstream.
I guess you are uploading v11.0.3 for unstable?
Sure. I was about to do that but got issues with internet connectivity
and went off doing something else, and forgot to do that later :)
Doing it right now.
Thanks!
/mjt