From fd3b0a54cba850267bd5f7ed0ac9f66f91aa44ac Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 14 Aug 2022 16:09:07 +0000 Subject: [ GLSA 202208-27 ] QEMU: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/733448 Bug: https://bugs.gentoo.org/736605 Bug: https://bugs.gentoo.org/773220 Bug: https://bugs.gentoo.org/775713 Bug: https://bugs.gentoo.org/780816 Bug: https://bugs.gentoo.org/792624 Bug: https://bugs.gentoo.org/807055 Bug: https://bugs.gentoo.org/810544 Bug: https://bugs.gentoo.org/820743 Bug: https://bugs.gentoo.org/835607 Bug: https://bugs.gentoo.org/839762 Signed-off-by: GLSAMaker Signed-off-by: Sam James --- glsa-202208-27.xml | 85 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 85 insertions(+) create mode 100644 glsa-202208-27.xml diff --git a/glsa-202208-27.xml b/glsa-202208-27.xml new file mode 100644 index 0000000..474faac --- /dev/null +++ b/glsa-202208-27.xml @@ -0,0 +1,85 @@ + + + + QEMU: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in QEMU, the worst of which could result in remote code execution (guest sandbox escape). + qemu + 2022-08-14 + 2022-08-14 + 733448 + 736605 + 773220 + 775713 + 780816 + 792624 + 807055 + 810544 + 820743 + 835607 + 839762 + remote + + + 7.0.0 + 7.0.0 + + + +

QEMU is a generic and open source machine emulator and virtualizer.

+
+ +

Multiple vulnerabilities have been discovered in QEMU.Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All QEMU users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/qemu-7.0.0" + +
+ + CVE-2020-15859 + CVE-2020-15863 + CVE-2020-16092 + CVE-2020-35504 + CVE-2020-35505 + CVE-2020-35506 + CVE-2020-35517 + CVE-2021-3409 + CVE-2021-3416 + CVE-2021-3527 + CVE-2021-3544 + CVE-2021-3545 + CVE-2021-3546 + CVE-2021-3582 + CVE-2021-3607 + CVE-2021-3608 + CVE-2021-3611 + CVE-2021-3682 + CVE-2021-3713 + CVE-2021-3748 + CVE-2021-3750 + CVE-2021-3929 + CVE-2021-3930 + CVE-2021-3947 + CVE-2021-4145 + CVE-2021-4158 + CVE-2021-4206 + CVE-2021-4207 + CVE-2021-20203 + CVE-2021-20257 + CVE-2021-20263 + CVE-2022-0358 + CVE-2022-26353 + CVE-2022-26354 + + ajak + sam +
\ No newline at end of file -- cgit v1.2.3-18-g5258