ELA-364-1 qemu security update

multiple vulnerabilities

2021-02-16
Packageqemu
Version1:2.1+dfsg-12+deb8u19
Related CVEs CVE-2020-11947 CVE-2020-15469 CVE-2020-15859 CVE-2020-25084 CVE-2020-29130 CVE-2020-29443 CVE-2021-20181 CVE-2021-20221


Several vulnerabilities were discovered in QEMU, a fast processor emulator (notably used in KVM and Xen HVM virtualization). An attacker could trigger a denial-of-service (DoS), information leak, and possibly execute arbitrary code with the privileges of the QEMU process on the host.



For Debian 8 jessie, these problems have been fixed in version 1:2.1+dfsg-12+deb8u19.

We recommend that you upgrade your qemu packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.