diff --git a/qemu.spec b/qemu.spec index 66de504..78afccf 100644 --- a/qemu.spec +++ b/qemu.spec @@ -334,6 +334,9 @@ Patch0321: vhost-user-gpu-fix-memory-leak-in-virgl_cmd_resource.patch Patch0322: vhost-user-gpu-fix-memory-leak-in-virgl_resource_att.patch Patch0323: vhost-user-gpu-fix-memory-disclosure-in-virgl_cmd_ge.patch Patch0324: vhost-user-gpu-fix-OOB-write-in-virgl_cmd_get_capset.patch +Patch0325: ide-ahci-add-check-to-avoid-null-dereference-CVE-201.patch +Patch0326: hw-intc-arm_gic-Fix-interrupt-ID-in-GICD_SGIR-regist.patch +Patch0327: usb-limit-combined-packets-to-1-MiB-CVE-2021-3527.patch BuildRequires: flex BuildRequires: bison @@ -727,6 +730,11 @@ getent passwd qemu >/dev/null || \ %endif %changelog +* Mon Jun 21 2021 Chen Qun +- ide: ahci: add check to avoid null dereference (CVE-2019-12067) +- hw/intc/arm_gic: Fix interrupt ID in GICD_SGIR register +- usb: limit combined packets to 1 MiB (CVE-2021-3527) + * Tue Jun 15 2021 Chen Qun - vhost-user-gpu: fix resource leak in 'vg_resource_create_2d' (CVE-2021-3544) - vhost-user-gpu: fix memory leak in vg_resource_attach_backing (CVE-2021-3544)