File _patchinfo of Package patchinfo.35260
<patchinfo incident="35260"> <issue tracker="bnc" id="1215311">qemu will stop compiling when binutils update is released (toolchain update 2023)</issue> <issue tracker="bnc" id="1227322">VUL-0: CVE-2024-4467: qemu: 'qemu-img info' leads to host file read/write</issue> <issue tracker="bnc" id="1212968">VUL-0: CVE-2023-2861: qemu,kvm: 9pfs: improper access control on special files</issue> <issue tracker="cve" id="2023-2861"/> <issue tracker="cve" id="2024-4467"/> <packager>dfaggioli</packager> <rating>important</rating> <category>security</category> <summary>Security update for qemu</summary> <description>This update for qemu fixes the following issues: - CVE-2023-2861: Fixed improper access control on special files via 9p protocol (bsc#1212968) - CVE-2024-4467: Fixed denial of service and file read/write via qemu-img info command (bsc#1227322) Other fixes: - Fixed qemu build compilation with binutils 2.41 upgrade (bsc#1215311) </description> </patchinfo>