On Mon, Jul 27 2026, Christian Borntraeger <[email protected]> wrote:

> Am 27.07.26 um 14:14 schrieb Cornelia Huck:
>> On Mon, Jul 27 2026, Christian Borntraeger <[email protected]> wrote:
>> 
>>> Cornelia, Eric, Matt,
>>>
>>> here are 5 more fixes for hardening QEMU against invalid input. Nothing
>>> is strictly a security issues as defined in the policy. For example
>>> https://qemu-project.gitlab.io/qemu/system/security.html says assert /
>>> abort: If triggering the code path requires kernel privileges (or root
>>> account access) in the guest, asserts/aborts in QEMU are a self
>>> inflicted denial of service. These will not be treated as security
>>> flaws, at most hardening bugs.
>>> And if anyone can provide invalid boot loader content it can provide
>>> anything to boot if secure boot is not available.
>>> We should fix those anyway, probably even for 11.1
>> 
>> Fixing: yes. For 11.1: how easy are they to trigger? For the bios fixes,
>> I assume you need a broken/crafted disk image; I assume that for the
>> other two, you need some buggy/misbehaving guest. Did you actually
>> manage to trigger this via some kind of test case?
>
> Easy to trigger, but only with modified guests or modified zipls. Normal
> guests will not trigger those.

Ok, so I think these would be suitable for the next release, but maybe
with a cc:stable.


Reply via email to