[ GLSA 202208-27 ] QEMU: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166049335212.12.6282922401954977921@7b72ab9f548d>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202208-27
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: QEMU: Multiple Vulnerabilities
     Date: August 14, 2022
     Bugs: #733448, #736605, #773220, #775713, #780816, #792624, #807055, #810544, #820743, #835607, #839762
       ID: 202208-27

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in QEMU, the worst of
which could result in remote code execution (guest sandbox escape).

Background
==========

QEMU is a generic and open source machine emulator and virtualizer.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  app-emulation/qemu         < 7.0.0                      >= 7.0.0

Description
===========

Multiple vulnerabilities have been discovered in QEMU.Please review the
CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All QEMU users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-emulation/qemu-7.0.0"

References
==========

[ 1 ] CVE-2020-15859
      https://nvd.nist.gov/vuln/detail/CVE-2020-15859
[ 2 ] CVE-2020-15863
      https://nvd.nist.gov/vuln/detail/CVE-2020-15863
[ 3 ] CVE-2020-16092
      https://nvd.nist.gov/vuln/detail/CVE-2020-16092
[ 4 ] CVE-2020-35504
      https://nvd.nist.gov/vuln/detail/CVE-2020-35504
[ 5 ] CVE-2020-35505
      https://nvd.nist.gov/vuln/detail/CVE-2020-35505
[ 6 ] CVE-2020-35506
      https://nvd.nist.gov/vuln/detail/CVE-2020-35506
[ 7 ] CVE-2020-35517
      https://nvd.nist.gov/vuln/detail/CVE-2020-35517
[ 8 ] CVE-2021-3409
      https://nvd.nist.gov/vuln/detail/CVE-2021-3409
[ 9 ] CVE-2021-3416
      https://nvd.nist.gov/vuln/detail/CVE-2021-3416
[ 10 ] CVE-2021-3527
      https://nvd.nist.gov/vuln/detail/CVE-2021-3527
[ 11 ] CVE-2021-3544
      https://nvd.nist.gov/vuln/detail/CVE-2021-3544
[ 12 ] CVE-2021-3545
      https://nvd.nist.gov/vuln/detail/CVE-2021-3545
[ 13 ] CVE-2021-3546
      https://nvd.nist.gov/vuln/detail/CVE-2021-3546
[ 14 ] CVE-2021-3582
      https://nvd.nist.gov/vuln/detail/CVE-2021-3582
[ 15 ] CVE-2021-3607
      https://nvd.nist.gov/vuln/detail/CVE-2021-3607
[ 16 ] CVE-2021-3608
      https://nvd.nist.gov/vuln/detail/CVE-2021-3608
[ 17 ] CVE-2021-3611
      https://nvd.nist.gov/vuln/detail/CVE-2021-3611
[ 18 ] CVE-2021-3682
      https://nvd.nist.gov/vuln/detail/CVE-2021-3682
[ 19 ] CVE-2021-3713
      https://nvd.nist.gov/vuln/detail/CVE-2021-3713
[ 20 ] CVE-2021-3748
      https://nvd.nist.gov/vuln/detail/CVE-2021-3748
[ 21 ] CVE-2021-3750
      https://nvd.nist.gov/vuln/detail/CVE-2021-3750
[ 22 ] CVE-2021-3929
      https://nvd.nist.gov/vuln/detail/CVE-2021-3929
[ 23 ] CVE-2021-3930
      https://nvd.nist.gov/vuln/detail/CVE-2021-3930
[ 24 ] CVE-2021-3947
      https://nvd.nist.gov/vuln/detail/CVE-2021-3947
[ 25 ] CVE-2021-4145
      https://nvd.nist.gov/vuln/detail/CVE-2021-4145
[ 26 ] CVE-2021-4158
      https://nvd.nist.gov/vuln/detail/CVE-2021-4158
[ 27 ] CVE-2021-4206
      https://nvd.nist.gov/vuln/detail/CVE-2021-4206
[ 28 ] CVE-2021-4207
      https://nvd.nist.gov/vuln/detail/CVE-2021-4207
[ 29 ] CVE-2021-20203
      https://nvd.nist.gov/vuln/detail/CVE-2021-20203
[ 30 ] CVE-2021-20257
      https://nvd.nist.gov/vuln/detail/CVE-2021-20257
[ 31 ] CVE-2021-20263
      https://nvd.nist.gov/vuln/detail/CVE-2021-20263
[ 32 ] CVE-2022-0358
      https://nvd.nist.gov/vuln/detail/CVE-2022-0358
[ 33 ] CVE-2022-26353
      https://nvd.nist.gov/vuln/detail/CVE-2022-26353
[ 34 ] CVE-2022-26354
      https://nvd.nist.gov/vuln/detail/CVE-2022-26354

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202208-27

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmL5HicACgkQFMQkOaVy
+9mEURAAw+j/7zDiMCXYIKkFosL2nhhMPalFXPjZf37AWWhuWOLqqKaGybB8/oQQ
BV4tDFPOx0avvDse+bHSMNItNK+ZLRx5nm3/35TYleVE8eoZ1GFFP6e258DNvJdK
/qcTnzrwYdbefoqJ5832NlEROkOaA9Ja0ljO5lfuWvEVb3S+JUPoOY/6Z2Os42lq
ouA+iNNWFFa8wfqTDryIOKSP5RZdo9Jz9G7IC7WRNj9O87DELCE4gFQMF1rntX41
h2byHUOjFXK//U3VL114jnnVJbjZT1cyvJh6jPybmyIWKfeEhmR7P7EVoE0JXShW
/9CcBsFchnRbCmLniZwnV3Uh2Vi9XZad+iZeaayr0L4iprSur+i4hWgdQKP3bG2T
3lWTg9QAIDG8m9yyBTXkxnpENyt41AnF+3xr9hqMi27PZJlDxBkGOt9rlIrIweVS
YhDFi/a461u7Y+VDpfpeHIH27RZvuOtqO0JaWVDNzZvqSa381S3zJVs/GH/3cZA+
xh7XIH4fsRfLSaeOh9BKRdQwIEM7eiQ1Zy1yIu8G9mys+OeKJXjFbBVrG7SN+ew0
MW+FTwhwp/ge1Si/bQRrg6KddDVOC5xsnBQTKr32HDxXKnBD63vf3wVhNCASGQD4
RQs861+fUgTtTqq9wKJZQYNi9+WNAemDnGI9yZF+IlqNwNOLNUQ=
=kuxq
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.