Debian 10020 Published by

A qemu security update has been released for Debian GNU/Linux 8 and 9 Extended LTS to address multiple vulnerabilities.

ELA-705-1 qemu security update

Package qemu
Version 1:2.1+dfsg-12+deb8u23 (jessie), 1:2.8+dfsg-6+deb9u18 (stretch)
Related CVEs CVE-2020-35504 CVE-2020-35505 CVE-2021-3507 CVE-2021-4206 CVE-2021-4207 CVE-2022-0216

Multiple vulnerabilities were found in QEMU, a fast processor emulator, which could result in denial of service or the execution of arbitrary code.

In addition, the jessie package addresses CVE-2021-3930, a denial of service vulnerability in the SCSI device emulation.

For Debian 8 jessie, these problems have been fixed in version 1:2.1+dfsg-12+deb8u23.

For Debian 9 stretch, these problems have been fixed in version 1:2.8+dfsg-6+deb9u18.

We recommend that you upgrade your qemu packages.

Further information about Extended LTS security advisories can be found at: debian Extended Long term support

  ELA-705-1 qemu security update