| Package | qemu |
|---|---|
| Version | 1:2.1+dfsg-12+deb8u16 |
| Related CVEs | CVE-2020-13659 CVE-2020-15863 |
There were two following CVE(s) reported against src:qemu.
-
CVE-2020-13659:address_space_mapinexec.cin QEMU 4.2.0 can trigger a NULL pointer dereference related toBounceBuffer. -
CVE-2020-15863: stack-based overflow inxgmac_enet_send()inhw/net/xgmac.c.
For Debian 8 jessie, these problems have been fixed in version 1:2.1+dfsg-12+deb8u16.
We recommend that you upgrade your qemu packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.