Changelog for
qemu-user-static-3.0.1-4.fc29.i686.rpm :
* Thu Jun 20 2019 Cole Robinson
- 2:3.0.1-4- CVE-2019-12155: qxl: null pointer dereference while releasing spice resources (bz #1712727, bz #1712670)- CVE-2019-5008: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS (bz #1705916, bz #1705915)- CVE-2018-20815: device_tree: heap buffer overflow while loading device tree blob (bz #1693117, bz #1693101)
* Tue May 14 2019 Daniel P. Berrangé - 2:3.0.1-3- Define md-clear CPUID bit- Resolves: rhbz #1710002 (CVE-2018-12126), rhbz #1710004 (CVE-2018-12127), rhbz #1710003 (CVE-2018-12130), rhbz #1710006 (CVE-2019-11091)
* Wed Apr 17 2019 Cole Robinson - 2:3.0.1-2- Fix nvme endianess issues
* Tue Apr 16 2019 Cole Robinson - 2:3.0.1-1- Update to qemu 3.0.1
* Thu Mar 21 2019 Cole Robinson - 2:3.0.0-4- CVE-2018-19364: 9pfs: use-after-free (bz #1651359)- CVE-2018-19489: 9pfs: use-after-free renaming files (bz #1653157)- CVE-2018-16867: usb-mtp: path traversal issue (bz #1656746)- CVE-2018-16872: usb-mtp: path traversal issue (bz #1659150)- CVE-2018-20191: pvrdma: uar_read leads to NULL deref (bz #1660315)- CVE-2019-6778: slirp: heap buffer overflow (bz #1669072)- CVE-2019-3812: Out-of-bounds read in hw/i2c/i2c-ddc.c allows for memory disclosure (bz #1678081)
* Tue Dec 18 2018 Adam Williamson - 2:3.0.0-3- Restore patch to drop phantom 86 key from en-us keymap (bz #1658676)
* Fri Nov 16 2018 Cole Robinson - 2:3.0.0-2- Fix cpu model crash on AMD hosts (bz #1640140)- CVE-2018-15746: seccomp blacklist is not applied to all threads (bz - Fix assertion in address_space_stw_le_cached (bz #1644728)- CVE-2018-10839: ne2000: fix possible out of bound access (bz #1636429)- CVE-2018-17958: rtl8139: fix possible out of bound access (bz #1636729)- CVE-2018-17962: pcnet: fix possible buffer overflow (bz #1636775)- CVE-2018-17963: net: ignore packet size greater than INT_MAX (bz #1636782)- CVE-2018-18849: lsi53c895a: OOB msg buffer access leads to DoS (bz - CVE-2018-18954: ppc64: Out-of-bounds r/w stack access in pnv_lpc_do_eccb (bz #1645442)
* Wed Aug 15 2018 Cole Robinson - 2:3.0.0-1- Rebase to qemu-3.0.0 GA
* Mon Aug 13 2018 Cole Robinson - 2:3.0.0-0.2.rc3- Drop ksm package, moved to ksmtuned srpm
* Tue Jul 31 2018 Cole Robinson - 2:3.0.0-0.1.rc3- Rebase to qemu-3.0.0-rc3- Drop now unneeded s390x conf (bz #1609706)- Only install modprobe kvm.conf on x86 (bz #1517989)
* Fri Jul 13 2018 Peter Robinson 2:2.12.0-4- Rebuild for Xen 4.11
* Mon Jun 18 2018 Daniel P. Berrangé - 2:2.12.0-3- New CPU features for speculative store bypass (CVE-2018-3639)
* Tue Jun 05 2018 Cole Robinson - 2:2.12.0-2- Fix qxl memslot_get_virt crashes (bz #1565354)
* Mon Apr 30 2018 Cole Robinson - 2:2.12.0-1- Update to qemu-2.12.0 GA
* Mon Apr 16 2018 Richard W.M. Jones - 2:2.12.0-0.7.rc3- Update to qemu-2.12.0-rc3- Remove upstream patch.- Fixes issues with partition / LV minimum alignment (RHBZ#1565714).
* Thu Apr 05 2018 Cole Robinson - 2:2.12.0-0.6.rc2- Update to qemu-2.12.0-rc2
* Wed Mar 28 2018 Cole Robinson - 2:2.12.0-0.5.rc1- Update to qemu-2.12.0-rc1
* Mon Mar 26 2018 Cole Robinson - 2:2.12.0-0.4.rc0- Enable missing tilegx, xtensa
* qemu-user targets
* Sun Mar 25 2018 Cole Robinson - 2:2.12.0-0.3.rc0- Generate binfmt configs with qemu-binfmt-conf.sh
* Fri Mar 23 2018 Cole Robinson - 2:2.12.0-0.2.rc0- Fix audio and ui module RPM deps- Drop some arch restrictions for rdma, spice, xen, numactl- Fix hppa firmware packaging
* Thu Mar 22 2018 Cole Robinson - 2:2.12.0-0.1.rc0- Rebase to qemu-2.12.0-rc0- Add hppa and riscv32/64 targets- Add audio and ui modules
* Mon Mar 19 2018 Daniel P. Berrangé - 2:2.11.1-2- Re-enable normal hardened build macros to fix ksmctl.c hardening- Don\'t strip _FORTIFY_SOURCE from compiler flags- Don\'t pass -pie as an extra ldflags when we use --enable-pie
* Wed Feb 28 2018 Cole Robinson - 2:2.11.1-1- Rebase to qemu 2.11.1 bugfix release
* Tue Feb 27 2018 Daniel P. Berrange - 2:2.11.0-5- Improve License tag- Honour CC/LD flags for ksmctl- Fix non-deterministic test failure- Use explicit \"python2\" binary to avoid \"python\" brokeness (rhbz#1550010)- Avoid breakage in TLS tests due to stricter crypto policies
* Fri Feb 09 2018 Fedora Release Engineering - 2:2.11.0-4.1- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Thu Dec 21 2017 Daniel P. Berrange - 2:2.11.0-4- Re-enable RBD on arm/ppc (rhbz #1528378)
* Wed Dec 20 2017 Adam Williamson - 2:2.11.0-3- Fix problem with typing some characters via VNC (LP#1738283)
* Wed Dec 20 2017 Cole Robinson - 2:2.11.0-2- Rebuild for xen 4.10
* Mon Dec 18 2017 Cole Robinson - 2:2.11.0-1- Rebase to 2.11.0 GA
* Mon Dec 04 2017 Cole Robinson - 2:2.11.0-0.3-rc3- Rebase to 2.11.0-rc3
* Tue Nov 28 2017 Paolo Bonzini - 2:2.11.0-0.2.rc2- Fix compilation- Upgrade qemu-ga packaging based on RHEL 7
* Mon Nov 20 2017 Cole Robinson - 2:2.11.0-0.1.rc1- Rebase to 2.11.0-rc1
* Thu Oct 19 2017 Cole Robinson - 2:2.10.1-1- Fix ppc64 KVM failure (bz #1501936)- CVE-2017-15038: 9p: information disclosure when reading extended attributes (bz #1499111)- CVE-2017-15268: potential memory exhaustion via websock connection to VNC (bz #1496882)
* Tue Oct 17 2017 Paolo Bonzini - 2:2.10.0-7- Update patch 1014 for new libmultipath/libmpathpersist API- Force build to fail if multipath is not available- Tighten permissions on the qemu-pr-helper socket
* Mon Oct 09 2017 Daniel P. Berrange - 2:2.10.0-6- Rebuild for libiscsi changed soname again
* Tue Oct 03 2017 Paolo Bonzini - 2:2.10.0-5- Rebuild with new libiscsi for iSER support
* Thu Sep 28 2017 Paolo Bonzini - 2:2.10.0-4- Stop using tcmalloc, glibc got faster
* Fri Sep 22 2017 Paolo Bonzini - 2:2.10.0-3- Backport persistent reservation manager in preparation for SELinux work- Fix previous patch
* Mon Sep 18 2017 Nathaniel McCallum - 2:2.10.0-2- Fix endianness of e_type in the ppc64le binfmt
* Thu Sep 07 2017 Cole Robinson - 2:2.10.0-1- Rebase to 2.10.0 GA
* Tue Aug 29 2017 Nathaniel McCallum - 2:2.10.0-0.5.rc4- Fix incorrect byte order in e_machine field in ppc64le binfmt (#1486379)
* Fri Aug 25 2017 Cole Robinson - 2:2.10.0-0.4.rc4- Rebase to 2.10.0-rc4
* Tue Aug 22 2017 Adam Williamson - 2:2.10.0-0.3.rc3- Don\'t build against rdma on 32-bit ARM (#1484155)
* Wed Aug 16 2017 Cole Robinson - 2:2.10.0-0.2.rc3- Rebase to 2.10.0-rc3
* Thu Aug 03 2017 Cole Robinson - 2:2.10.0-0.1.rc1- Rebase to 2.10.0-rc1
* Sun Jul 30 2017 Florian Weimer - 2:2.9.0-9- Rebuild with binutils fix for ppc64le (#1475636)
* Tue Jul 25 2017 Daniel Berrange - 2:2.9.0-8- Disabled RBD on arm & ppc64 (rhbz #1474743)
* Thu Jul 20 2017 Nathaniel McCallum - 2:2.9.0-7- Fix binfmt dependencies and post scriptlets- Add binfmt for ppc64le
* Wed Jul 19 2017 Daniel Berrange - 2:2.9.0-6- Fixes for compat with Xen 4.9
* Tue Jul 18 2017 Nathaniel McCallum - 2:2.9.0-5- Fix ucontext_t references
* Tue Jul 18 2017 Daniel P. Berrange - 2:2.9.0-4- Rebuild for changed Xen sonames
* Wed Jul 12 2017 Cole Robinson - 2:2.9.0-3- CVE-2017-8112: vmw_pvscsi: infinite loop in pvscsi_log2 (bz #1445622)- CVE-2017-8309: audio: host memory lekage via capture buffer (bz #1446520)- CVE-2017-8379: input: host memory lekage via keyboard events (bz #1446560)- CVE-2017-8380: scsi: megasas: out-of-bounds read in megasas_mmio_write (bz - CVE-2017-7493: 9pfs: guest privilege escalation in virtfs mapped-file mode (bz #1451711)- CVE-2017-9503: megasas: null pointer dereference while processing megasas command (bz #1459478)- CVE-2017-10806: usb-redirect: stack buffer overflow in debug logging (bz - CVE-2017-9524: nbd: segfault due to client non-negotiation (bz #1460172)- CVE-2017-10664: qemu-nbd: server breaks with SIGPIPE upon client abort (bz