On 7/26/26 19:20, Salvatore Bonaccorso wrote:
Hi Michael,

On Sun, Jul 26, 2026 at 04:42:22PM +0200, Salvatore Bonaccorso wrote:
Hi Michael,

On Sat, Jul 25, 2026 at 10:06:29AM +0300, Michael Tokarev wrote:
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:qemu
User: [email protected]
Usertags: pu

[ Reason ]
New upstream stable/bugfix release.  With more than 120 fixes all
over the places, - fixing bugs, correctness.  Including the following
CVE fixes:
  CVE-2026-8348 CVE-2026-9238 CVE-2026-15578 CVE-2026-15705
  CVE-2026-16043 CVE-2026-48002 CVE-2026-61475 CVE-2026-63319

Is this the correct set of CVEs for this round? I'm asking because
CVE-2026-48002 was already fixed with 1:10.0.11+ds-0+deb13u1 ?

Okay that one consist of 3 commits, two of wich were in the earlier
release and the last one in v10.0.12 upstream.

Here's the source of confusion, and the fact stable releases actually
happened in-between (which is described in the next message):

https://lore.kernel.org/qemu-devel/CAMxuvaxUWc=qr9pqq6ww6xnazp4mf77aypcfuxvret1kl_w...@mail.gmail.com/

so yeah, it's two halves of the same issue.

I guess you are uploading v11.0.3 for unstable?

And I forgot to add the changelog for the changes in 11.0.3,
with all the CVEs mentioned in there.  I'm sorry for this,
but it's already uploaded.  I'm a bit too tired today for a
good work.

From the git log v11.0.2..v11.0.3:

CVE-2026-8348
CVE-2026-9238
CVE-2026-15705
CVE-2026-15578
CVE-2026-16043 (the same doubling)
CVE-2026-48002
CVE-2026-63319
CVE-2026-61475

so it's the same set.

Thanks,

/mjt

Reply via email to