On 7/26/26 19:20, Salvatore Bonaccorso wrote:
Hi Michael,
On Sun, Jul 26, 2026 at 04:42:22PM +0200, Salvatore Bonaccorso wrote:
Hi Michael,
On Sat, Jul 25, 2026 at 10:06:29AM +0300, Michael Tokarev wrote:
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:qemu
User: [email protected]
Usertags: pu
[ Reason ]
New upstream stable/bugfix release. With more than 120 fixes all
over the places, - fixing bugs, correctness. Including the following
CVE fixes:
CVE-2026-8348 CVE-2026-9238 CVE-2026-15578 CVE-2026-15705
CVE-2026-16043 CVE-2026-48002 CVE-2026-61475 CVE-2026-63319
Is this the correct set of CVEs for this round? I'm asking because
CVE-2026-48002 was already fixed with 1:10.0.11+ds-0+deb13u1 ?
Okay that one consist of 3 commits, two of wich were in the earlier
release and the last one in v10.0.12 upstream.
Here's the source of confusion, and the fact stable releases actually
happened in-between (which is described in the next message):
https://lore.kernel.org/qemu-devel/CAMxuvaxUWc=qr9pqq6ww6xnazp4mf77aypcfuxvret1kl_w...@mail.gmail.com/
so yeah, it's two halves of the same issue.
I guess you are uploading v11.0.3 for unstable?
And I forgot to add the changelog for the changes in 11.0.3,
with all the CVEs mentioned in there. I'm sorry for this,
but it's already uploaded. I'm a bit too tired today for a
good work.
From the git log v11.0.2..v11.0.3:
CVE-2026-8348
CVE-2026-9238
CVE-2026-15705
CVE-2026-15578
CVE-2026-16043 (the same doubling)
CVE-2026-48002
CVE-2026-63319
CVE-2026-61475
so it's the same set.
Thanks,
/mjt