On 10/4/26 21:28, Salvatore Bonaccorso wrote:
Hi Michael,

On Sat, Oct 03, 2026 at 08:19:03PM +0300, Michael Tokarev wrote:
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected]
Control: affects -1 + src:qemu
User: [email protected]
Usertags: pu

[ Reason ]
There's a new upstream stable/bugfix release, with a number
of security and correctness fixes.  Security fixes include:
CVE-2026-17588, CVE-2026-93834 (#1149064), CVE-2026-12080,
CVE-2026-66899, CVE-2026-66900, CVE-2026-66020, CVE-2026-84788,
CVE-2026-81627 (#1148473), CVE-2026-77913, CVE-2026-16271.

One small remark, CVE-2026-66020 is not yet fixed in unstable.

It is
https://gitlab.com/qemu-project/qemu/-/commit/3ece85b53c124142c7d5cbb1165d4da125b7c369
and backported to v10.0.14, via
https://gitlab.com/qemu-project/qemu/-/commit/8eebc546bbd54fdd7b6fa2ebb3b54036ab397564
but v11.1.2 misses it yet AFAICS.

Heck. Indeed, I missed that single commit in 11.1.x series.  What a shame.
It will be included in next upstream 11.1.3 release, at about Oct-25, -
I already queued it up after this your note.

I can make a new upload for sid with this single commit on top of 11.1.2,
hopefully it will be enough to keep the peace.

Thank you for spotting it!

Things becomes more and more difficult with the number of changes
increasing (though the September series were smaller than before).
I wonder how come I missed it.  I'll try to find out :)

/mjt

Reply via email to