[Secure-testing-team] Bug#847951: qemu: CVE-2016-9911: usb: ehci: memory leakage in ehci_init_transfer

Salvatore Bonaccorso carnil at debian.org
Mon Dec 12 15:26:30 UTC 2016


Source: qemu
Version: 1:2.7+dfsg-3
Severity: important
Tags: security upstream patch
Control: found -1 1:2.1+dfsg-11

Hi,

the following vulnerability was published for qemu.

CVE-2016-9911[0]:
usb: ehci: memory leakage in ehci_init_transfer

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-9911
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9911
[1] http://git.qemu.org/?p=qemu.git;a=commitdiff;h=791f97758e223de3290592d
[2] http://www.openwall.com/lists/oss-security/2016/12/06/10

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Secure-testing-team mailing list