On Mon, Jul 27, 2026 at 09:52:21AM -0400, Stefan Hajnoczi wrote: > Hi, > QEMU v11.1.0-rc2 will be tagged tomorrow and -rc3 a week after that. > The project currently has a backlog of confidential and potentially > CVE-worthy bugs. Maintainers are triaging these bug reports and fixes > are being sent to the mailing list. > > Holding up the QEMU 11.1 release for any and all CVE fixes is not > realistic this time around since there are still a number of upcoming > fixes expected over the coming weeks. Many CVEs are low severity and > do not pose enough of a security risk to hold up the 11.1 release. > > I'd like to approach CVEs as follows: > 1. CVE fix authors and maintainers should indicate the severity in > cover letters. This will ensure that serious CVE fixes are included in > v11.1.0 while less serious CVEs do not hold up the release. > 2. Low severity CVE fixes should go into the -stable branch if they > cannot make it into v11.1.0. > > I will be looking at CVE fixes on a case-by-case when -rc3 is tagged. > If you feel a fix is critical, please let me know.
IMHO, we shouldn't do anything special wrt CVEs for the release. Just follow our normal bug evaluation criteria which get increasingly strict in later RC's, such that rc3 is largely just regression fixes. No matter how many CVE fixes we might try to rush into 11.1, all indications are that we're going to have countless more arrive on an ongoing basis for a good while yet and just have to accept that. With regards, Daniel -- |: https://berrange.com ~~ https://hachyderm.io/@berrange :| |: https://libvirt.org ~~ https://entangle-photo.org :| |: https://pixelfed.art/berrange ~~ https://fstop138.berrange.com :|
