package release.debian.org
tags 1146097 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: qemu
Version: 10.0.13+ds-0+deb13u1

Explanation: new upstream stable release; fix integer overflow issue 
[CVE-2026-15264]; fix secure boot bypass [CVE-2026-16288]; fix infinite loop 
[CVE-2026-16457]; fix buffer overflow issues [CVE-2026-17516 CVE-2026-50626 
CVE-2026-58581 CVE-2026-58582 CVE-2026-63110; virtio-gpu: reject requests with 
short/truncated control headers [CVE-2026-18054]; fix use-after-free issues 
[CVE-2026-50624 CVE-2026-63322 CVE-2026-63323]; fix out of bounds write issue 
[CVE-2026-61402]; hw/uefi: add post_load checks [CVE-2026-61404]; fix denial of 
service issues [CVE-2026-61405 CVE-2026-61406]; fix memory leak issue 
[CVE-2026-61476]; fix out of bounds read issues [CVE-2026-63109 CVE-2026-63320 
CVE-2026-65928 CVE-2026-65929 CVE-2026-66021]; fix 9pfs Readonly 
O_TRUNC/O_APPEND Bypass issue [CVE-2026-63318]; virtio: use masked features 
with set_features_ex [CVE-2026-63321]; virtio-net: qemu_bh_new_guarded uses 
wrong DeviceState, bypassing MMIO reentrancy protection [CVE-2026-66022]

Reply via email to