Errata overview
Errata ID 325
Date 2018-11-21
Source package qemu
Fixed in version 1:2.8+dfsg-6+deb9u5A~4.3.0.201811191133
Description
This update addresses the following issues:
* ne2000: integer overflow leads to buffer overflow issue (CVE-2018-10839)
* pcnet: integer overflow leads to buffer overflow (CVE-2018-17962)
* net: ignore packets with large size (CVE-2018-17963)
* Add support for "Speculative Storage Bypass Disable" (SSBD)
Additional notes
CVE ID CVE-2018-10839
CVE-2018-17962
CVE-2018-17963
UCS Bug number #48165