Hi, QEMU v11.1.0-rc2 will be tagged tomorrow and -rc3 a week after that. The project currently has a backlog of confidential and potentially CVE-worthy bugs. Maintainers are triaging these bug reports and fixes are being sent to the mailing list.
Holding up the QEMU 11.1 release for any and all CVE fixes is not realistic this time around since there are still a number of upcoming fixes expected over the coming weeks. Many CVEs are low severity and do not pose enough of a security risk to hold up the 11.1 release. I'd like to approach CVEs as follows: 1. CVE fix authors and maintainers should indicate the severity in cover letters. This will ensure that serious CVE fixes are included in v11.1.0 while less serious CVEs do not hold up the release. 2. Low severity CVE fixes should go into the -stable branch if they cannot make it into v11.1.0. I will be looking at CVE fixes on a case-by-case when -rc3 is tagged. If you feel a fix is critical, please let me know. Stefan
