Change log for qemu package in Ubuntu

175 of 566 results
Deleted in noble-proposed (Reason: roll back unnecessary transition)
qemu (1:8.2.2+ds-0ubuntu2) noble; urgency=medium

  * No-change rebuild against liburing2t64.

 -- Matthias Klose <email address hidden>  Fri, 19 Apr 2024 18:55:59 +0200
Published in oracular-release
Published in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.2.2+ds-0ubuntu1) noble; urgency=medium

  * Merge version 8.2.2 from upstream. (LP: #2061005).  Cherry-picks from
    Debian:
    - d/p/ui-clipboard-mark-type-as-not-available-when-no-data-CVE-2023-6683.patch:
      Remove patch; included upstream.
    - d/control: clarify qemu-system-gui description: this is not a
      management gui for qemu
    - d/rules: stop qemu-system-${arch} packages from providing
      themselves (#1063233)
    - d/control{,-in}: Fix typo on qemu-system-gui description.

 -- Sergio Durigan Junior <email address hidden>  Fri, 12 Apr 2024 18:13:51 -0400
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.2.1+ds-1ubuntu9) noble; urgency=medium

  * No-change rebuild for CVE-2024-3094

 -- William Grant <email address hidden>  Mon, 01 Apr 2024 18:20:15 +1100
Published in mantic-updates
Deleted in mantic-proposed (Reason: moved to -updates)
qemu (1:8.0.4+dfsg-1ubuntu3.23.10.5) mantic; urgency=medium

  * d/p/u/lp2012763-maxcpus-too-low.patch: Actually set the max_cpus
    property of the new Mantic machine types. (LP: #2012763)

Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.2.1+ds-1ubuntu8) noble; urgency=medium

  * d/p/u/lp2012763-maxcpus-too-low.patch: Actually set the max_cpus
    property of the new Mantic machine types. (LP: #2012763)

 -- Sergio Durigan Junior <email address hidden>  Mon, 25 Mar 2024 14:58:39 -0400
Published in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.19) jammy; urgency=medium

  * d/p/u/lp2012763-maxcpus-too-low.patch: Bump max_cpus to 1024 on
    amd64.  (LP: #2012763)

 -- Sergio Durigan Junior <email address hidden>  Mon, 18 Mar 2024 16:38:25 -0400
Superseded in mantic-proposed
qemu (1:8.0.4+dfsg-1ubuntu3.23.10.4) mantic; urgency=medium

  * d/p/u/lp2012763-maxcpus-too-low.patch: Bump max_cpus to 1024 on
    amd64.  (LP: #2012763)

 -- Sergio Durigan Junior <email address hidden>  Mon, 18 Mar 2024 19:40:04 -0400
Superseded in noble-proposed
qemu (1:8.2.1+ds-1ubuntu7) noble; urgency=medium

  * d/p/u/lp2012763-maxcpus-too-low.patch: Bump max_cpus to 1024 on
    Jammy amd64 machine types.  (LP: #2012763)

 -- Sergio Durigan Junior <email address hidden>  Mon, 18 Mar 2024 16:48:22 -0400
Superseded in noble-proposed
qemu (1:8.2.1+ds-1ubuntu6) noble; urgency=medium

  * No-change rebuild against libcurl3t64-gnutls

 -- Steve Langasek <email address hidden>  Sat, 16 Mar 2024 07:16:54 +0000
Superseded in noble-proposed
qemu (1:8.2.1+ds-1ubuntu5) noble; urgency=medium

  * No-change rebuild against libglib2.0-0t64

 -- Steve Langasek <email address hidden>  Mon, 11 Mar 2024 23:31:21 +0000
Superseded in noble-proposed
qemu (1:8.2.1+ds-1ubuntu4) noble; urgency=medium

  * No-change rebuild against libgnutls30t64

 -- Steve Langasek <email address hidden>  Sun, 10 Mar 2024 02:11:43 +0000
Superseded in noble-proposed
qemu (1:8.2.1+ds-1ubuntu3) noble; urgency=medium

  * No-change rebuild against libpng16-16t64

 -- Steve Langasek <email address hidden>  Thu, 29 Feb 2024 07:54:00 +0000
Superseded in noble-proposed
qemu (1:8.2.1+ds-1ubuntu2) noble; urgency=medium

  * d/p/u/lp-2055003-*: Properly initialize max_cpus limit to
    SPAPR_IRQ_NR_IPIS, fixing a segfault on ppc64el. (LP: #2055003)

 -- Sergio Durigan Junior <email address hidden>  Mon, 26 Feb 2024 15:32:25 -0500
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.18) jammy; urgency=medium

  * d/p/u/lp-2046439-s390x-*.patch: Fix emulation of
    "COMPARE HALFWORD RELATIVE LONG" on s390x.
    (LP: #2046439)

 -- Sergio Durigan Junior <email address hidden>  Wed, 21 Feb 2024 15:44:50 -0500
Superseded in mantic-updates
Deleted in mantic-proposed (Reason: moved to -updates)
qemu (1:8.0.4+dfsg-1ubuntu3.23.10.3) mantic; urgency=medium

  * d/p/u/lp-2051965-*.patch: Fix QEMU crash when using TCG acceleration
    with guest Linux kernel >= 6.3. (LP: #2051965)

 -- Sergio Durigan Junior <email address hidden>  Tue, 13 Feb 2024 18:26:17 -0500
Deleted in noble-updates (Reason: superseded by release)
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.2.1+ds-1ubuntu1) noble; urgency=medium

  * Merge with Debian unstable (LP: #2051883, #2049703). Remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
    - d/rules: Enable/disable extra features on microvm
      variant. (LP #2045594)
    - Move glusterfs storage driver to Universe in a new package
      (LP #2045063):
      + d/control{,-in}: new package qemu-block-supplemental for drivers
        we want in Universe
      + d/rules: we only want block-gluster.so in the new
        qemu-block-supplemental package. Adjust dynamically-created
        maintainer scripts for qemu-block-extra and -supplemental.

Superseded in noble-proposed
qemu (1:8.2.0+ds-4ubuntu2) noble; urgency=medium

  * Move glusterfs storage driver to Universe in a new package
    (LP: #2045063):
    - d/control{,-in}: new package qemu-block-supplemental for drivers
      we want in Universe
    - d/rules: we only want block-gluster.so in the new
      qemu-block-supplemental package. Adjust dynamically-created
      maintainer scripts for qemu-block-extra and -supplemental.

 -- Andreas Hasenack <email address hidden>  Fri, 02 Feb 2024 14:07:00 -0300
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.17) jammy; urgency=medium

  * d/rules: modify qemu-block-extra postinst to avoid
    restarting run-qemu.mount (LP: #2051153)

 -- Christian Ehrhardt <email address hidden>  Mon, 29 Jan 2024 11:43:30 +0100
Superseded in noble-proposed
qemu (1:8.2.0+ds-4ubuntu1) noble; urgency=medium

  * Merge with Debian unstable (LP: #2048802, #2048776). Remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
  * Drop changes:
    - d/p/u/lp2003673-*.patch: Enable passthrough of IBM Z crypto
      hardware to Secure Execution guests. (LP #2003673)
      [ Incorporated by upstream on version 8.2.0. ]
  * Add changes:
    - d/rules: Enable/disable extra features on microvm
      variant. (LP: #2045594)

 -- Sergio Durigan Junior <email address hidden>  Wed, 10 Jan 2024 19:10:46 -0500
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.1.3+ds-1ubuntu2) noble; urgency=medium

  * d/p/u/define-ubuntu-machine-types.patch: Remove -hpb Noble machine
    types, as they are not needed by OpenStack anymore. (LP: #2045592)

 -- Sergio Durigan Junior <email address hidden>  Mon, 04 Dec 2023 16:44:44 -0500
Published in focal-updates
Published in focal-security
qemu (1:4.2-3ubuntu6.28) focal-security; urgency=medium

  * SECURITY UPDATE: infinite loop in USB xHCI controller
    - debian/patches/CVE-2020-14394.patch: Fix unbounded loop in
      xhci_ring_chain_length() in hw/usb/hcd-xhci.c.
    - CVE-2020-14394
  * SECURITY UPDATE: code execution in TCG Accelerator
    - debian/patches/CVE-2020-24165.patch: fix race in cpu_exec_step_atomic
      in accel/tcg/cpu-exec.c.
    - CVE-2020-24165
  * SECURITY UPDATE: OOB access in ATI VGA device
    - debian/patches/CVE-2021-3638.patch: Fix buffer overflow in ati_2d_blt
      in hw/display/ati_2d.c.
    - CVE-2021-3638
  * SECURITY UPDATE: OOB read in RDMA device
    - debian/patches/CVE-2023-1544.patch: protect against buggy or
      malicious guest driver in hw/rdma/vmw/pvrdma_main.c.
    - CVE-2023-1544
  * SECURITY UPDATE: 9pfs special file access
    - debian/patches/CVE-2023-2861.patch: prevent opening special files in
      fsdev/virtfs-proxy-helper.c, hw/9pfs/9p-util.h.
    - CVE-2023-2861
  * SECURITY UPDATE: heap overflow in crypto device
    - debian/patches/CVE-2023-3180.patch: verify src&dst buffer length for
      sym request in hw/virtio/virtio-crypto.c.
    - CVE-2023-3180
  * SECURITY UPDATE: DoS in VNC server
    - debian/patches/CVE-2023-3354.patch: remove io watch if TLS channel is
      closed during handshake in include/io/channel-tls.h,
      io/channel-tls.c.
    - CVE-2023-3354
  * SECURITY UPDATE: disk offset 0 access
    - debian/patches/CVE-2023-5088.patch: cancel async DMA operation before
      resetting state in hw/ide/core.c.
    - CVE-2023-5088

 -- Marc Deslauriers <email address hidden>  Thu, 30 Nov 2023 14:45:57 -0500
Superseded in jammy-updates
Published in jammy-security
qemu (1:6.2+dfsg-2ubuntu6.16) jammy-security; urgency=medium

  * SECURITY UPDATE: infinite loop in USB xHCI controller
    - debian/patches/CVE-2020-14394.patch: fix unbounded loop in
      hw/usb/hcd-xhci.c.
    - CVE-2020-14394
  * SECURITY UPDATE: OOB read in RDMA device
    - debian/patches/CVE-2023-1544.patch: protect against buggy or
      malicious guest driver in hw/rdma/vmw/pvrdma_main.c.
    - CVE-2023-1544
  * SECURITY UPDATE: 9pfs special file access
    - debian/patches/CVE-2023-2861.patch: prevent opening special files in
      fsdev/virtfs-proxy-helper.c, hw/9pfs/9p-util.h.
    - CVE-2023-2861
  * SECURITY UPDATE: heap overflow in crypto device
    - debian/patches/CVE-2023-3180.patch: verify src&dst buffer length for
      sym request in hw/virtio/virtio-crypto.c.
    - CVE-2023-3180
  * SECURITY UPDATE: infinite loop in VNC server
    - debian/patches/CVE-2023-3255.patch: fix infinite loop in
      inflate_buffer in ui/vnc-clipboard.c.
    - CVE-2023-3255
  * SECURITY UPDATE: race in virtio-net hot-unplug
    - debian/patches/CVE-2023-3301.patch: do not cleanup the vdpa/vhost-net
      structures if peer nic is present in net/vhost-vdpa.c.
    - CVE-2023-3301
  * SECURITY UPDATE: DoS in VNC server
    - debian/patches/CVE-2023-3354.patch: remove io watch if TLS channel is
      closed during handshake in include/io/channel-tls.h,
      io/channel-tls.c.
    - CVE-2023-3354
  * SECURITY UPDATE: disk offset 0 access
    - debian/patches/CVE-2023-5088.patch: cancel async DMA operation before
      resetting state in hw/ide/core.c.
    - CVE-2023-5088
  * SECURITY UPDATE: DoS in Intel HD Audio device
    - debian/patches/CVE-2021-3611-*.patch: add MemTxAttrs argument to
      DMA functions and use it in hw/audio/intel-hda.c.
    - CVE-2021-3611

 -- Marc Deslauriers <email address hidden>  Thu, 30 Nov 2023 09:53:27 -0500
Published in lunar-updates
Published in lunar-security
qemu (1:7.2+dfsg-5ubuntu2.4) lunar-security; urgency=medium

  * SECURITY UPDATE: OOB read in RDMA device
    - debian/patches/CVE-2023-1544.patch: protect against buggy or
      malicious guest driver in hw/rdma/vmw/pvrdma_main.c.
    - CVE-2023-1544
  * SECURITY UPDATE: 9pfs special file access
    - debian/patches/CVE-2023-2861.patch: prevent opening special files in
      fsdev/virtfs-proxy-helper.c, hw/9pfs/9p-util.h.
    - CVE-2023-2861
  * SECURITY UPDATE: heap overflow in crypto device
    - debian/patches/CVE-2023-3180.patch: verify src&dst buffer length for
      sym request in hw/virtio/virtio-crypto.c.
    - CVE-2023-3180
  * SECURITY UPDATE: infinite loop in VNC server
    - debian/patches/CVE-2023-3255.patch: fix infinite loop in
      inflate_buffer in ui/vnc-clipboard.c.
    - CVE-2023-3255
  * SECURITY UPDATE: race in virtio-net hot-unplug
    - debian/patches/CVE-2023-3301.patch: do not cleanup the vdpa/vhost-net
      structures if peer nic is present in net/vhost-vdpa.c.
    - CVE-2023-3301
  * SECURITY UPDATE: DoS in VNC server
    - debian/patches/CVE-2023-3354.patch: remove io watch if TLS channel is
      closed during handshake in include/io/channel-tls.h,
      io/channel-tls.c.
    - CVE-2023-3354
  * SECURITY UPDATE: division by zero via scsi block size
    - debian/patches/CVE-2023-42467.patch: disallow block sizes smaller
      than 512 in hw/scsi/scsi-disk.c.
    - CVE-2023-42467
  * SECURITY UPDATE: disk offset 0 access
    - debian/patches/CVE-2023-5088.patch: cancel async DMA operation before
      resetting state in hw/ide/core.c.
    - CVE-2023-5088

 -- Marc Deslauriers <email address hidden>  Thu, 30 Nov 2023 08:34:55 -0500
Superseded in mantic-updates
Published in mantic-security
qemu (1:8.0.4+dfsg-1ubuntu3.23.10.2) mantic-security; urgency=medium

  * SECURITY UPDATE: OOB read in RDMA device
    - debian/patches/CVE-2023-1544.patch: protect against buggy or
      malicious guest driver in hw/rdma/vmw/pvrdma_main.c.
    - CVE-2023-1544
  * SECURITY UPDATE: null pointer deref in NVME device
    - debian/patches/CVE-2023-40360.patch: fix null pointer access in
      directive receive in hw/nvme/ctrl.c.
    - CVE-2023-40360
  * SECURITY UPDATE: OOB read in NVME device
    - debian/patches/CVE-2023-4135.patch: fix oob memory read in fdp events
      log in hw/nvme/ctrl.c.
    - CVE-2023-4135
  * SECURITY UPDATE: division by zero via scsi block size
    - debian/patches/CVE-2023-42467.patch: disallow block sizes smaller
      than 512 in hw/scsi/scsi-disk.c.
    - CVE-2023-42467
  * SECURITY UPDATE: disk offset 0 access
    - debian/patches/CVE-2023-5088.patch: cancel async DMA operation before
      resetting state in hw/ide/core.c.
    - CVE-2023-5088

 -- Marc Deslauriers <email address hidden>  Thu, 30 Nov 2023 08:22:57 -0500
Superseded in noble-proposed
qemu (1:8.1.3+ds-1ubuntu1) noble; urgency=medium

  * Merge with Debian unstable (LP: #2044425, #2039700). Remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
    - d/p/u/lp2003673-*.patch: Enable passthrough of IBM Z crypto
      hardware to Secure Execution guests. (LP #2003673)
  * Drop changes:
    - d/rules: Incorporate the following changes from Debian unstable, in
      order to fix the FTBFS caused by -fcf-protection:
      + d/rules: move icons install rules to install-misc section
      + d/rules: stop running whole thing with dh, take back *-indep sequence
      + d/rules: implement arch-dependent install/build targets without dh too
      [ Fixed in Debian. ]
    - d/rules: Get rid of binary-helper target; explicitly invoke its
      commands under binary-{arch,indep}.  This makes the build succeed
      again in Ubuntu, where binary-helper wasn't being properly invoked.
      [ Fixed in Debian. ]
    - d/p/u/lp2003673-update-linux-headers-6.3rc5.patch,
      d/p/u/lp2003673-update-linux-headers-6.5rc1.patch,
      d/p/u/lp2003673-s390x-fix-missing-subsystem-reset-registration.patch:
      Drop some of the patches to Enable passthrough of IBM Z crypto
      hardware to Secure Execution guests. (LP #2003673)
      [ Applied upstream. ]

 -- Sergio Durigan Junior <email address hidden>  Wed, 22 Nov 2023 21:34:19 -0500
Superseded in mantic-updates
Deleted in mantic-proposed (Reason: moved to -updates)
qemu (1:8.0.4+dfsg-1ubuntu3.23.10.1) mantic; urgency=medium

  * d/p/u/lp2003673-*.patch: Enable passthrough of IBM Z crypto
    hardware to Secure Execution guests. (LP: #2003673)

 -- Sergio Durigan Junior <email address hidden>  Mon, 30 Oct 2023 16:16:32 -0400
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.0.4+dfsg-1ubuntu5) noble; urgency=medium

  * d/p/u/lp2003673-*.patch: Enable passthrough of IBM Z crypto
    hardware to Secure Execution guests. (LP: #2003673)

 -- Sergio Durigan Junior <email address hidden>  Thu, 16 Nov 2023 10:35:58 -0500
Superseded in noble-release
Deleted in noble-proposed (Reason: Moved to noble)
qemu (1:8.0.4+dfsg-1ubuntu4) noble; urgency=medium

  * Rebuild against new libnfs14.

 -- Gianfranco Costamagna <email address hidden>  Fri, 27 Oct 2023 10:46:01 +0200
Superseded in noble-release
Published in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
qemu (1:8.0.4+dfsg-1ubuntu3) mantic; urgency=medium

  * d/rules: Get rid of binary-helper target; explicitly invoke its
    commands under binary-{arch,indep}.  This makes the build succeed
    again in Ubuntu, where binary-helper wasn't being properly invoked.

 -- Sergio Durigan Junior <email address hidden>  Tue, 03 Oct 2023 18:13:20 -0400
Superseded in mantic-proposed
qemu (1:8.0.4+dfsg-1ubuntu2) mantic; urgency=medium

  * d/rules: Incorporate the following changes from Debian unstable, in
    order to fix the FTBFS caused by -fcf-protection:
    - d/rules: implement arch-dependent install/build targets without dh too
    - d/rules: stop running whole thing with dh, take back *-indep sequence
    - d/rules: move icons install rules to install-misc section

 -- Sergio Durigan Junior <email address hidden>  Wed, 27 Sep 2023 14:53:27 -0400
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.15) jammy; urgency=medium

  * d/rules: remove --no-start for qemu-guest-agent (LP: #2028124)

 -- Mitchell Dzurick <email address hidden>  Fri, 15 Sep 2023 14:39:05 -0400
Superseded in lunar-updates
Deleted in lunar-proposed (Reason: moved to -updates)
qemu (1:7.2+dfsg-5ubuntu2.3) lunar; urgency=medium

  * d/rules: remove --no-start for qemu-guest-agent (LP: #2028124)

 -- Mitchell Dzurick <email address hidden>  Thu, 31 Aug 2023 05:38:41 -0700
Superseded in jammy-updates
Superseded in jammy-proposed
qemu (1:6.2+dfsg-2ubuntu6.14) jammy; urgency=medium

  * d/u/lp-2033957-virtiofsd-Fix-breakage-due-to-fuse_init_in.patch:
    Fix virtiofsd breakage due to fuse_init_in size change, which
    happened because of the Linux kernel 5.17 headers that were
    imported in a previous patch. (LP: #2033957)

 -- Sergio Durigan Junior <email address hidden>  Tue, 05 Sep 2023 22:58:36 -0400
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
qemu (1:8.0.4+dfsg-1ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable. Remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO

 -- Sergio Durigan Junior <email address hidden>  Mon, 14 Aug 2023 16:28:34 -0400
Superseded in mantic-proposed
qemu (1:8.0.3+dfsg-4ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable (LP: #2028873, #2028124). Remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO

 -- Sergio Durigan Junior <email address hidden>  Mon, 31 Jul 2023 23:09:27 -0400
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.13) jammy; urgency=medium

  * d/p/u/lp-1853307-*.patch: Backport patches to implement Enhanced
    Interpretation for PCI Functions (s390x).  (LP: #1853307)

 -- Sergio Durigan Junior <email address hidden>  Wed, 05 Jul 2023 10:47:05 -0400
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.12) jammy; urgency=medium

  [ Chengen Du ]
  * d/p/u/lp2025591-block-use-the-request-length-for-iov-alignment.patch:
    Fix boot error on the HWE 6.2 kernel with direct IO (eg, cache=none)
    if the logical block size is smaller than in the host (LP: #2025591)

 -- Mauricio Faria de Oliveira <email address hidden>  Mon, 03 Jul 2023 18:00:25 -0300
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
qemu (1:8.0.2+dfsg-2ubuntu1) mantic; urgency=medium

  * Merge with Debian unstable (LP: #2018103). Remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
  * Drop changes:
    - d/control-in: libnfs is in main since focal, enable direct nfs
      storage support (LP 1988704)
      [ Adopted by Debian. ]
    - d/control-in: libsndio is in universe in ubuntu
      [ Adopted by Debian. ]
    - Fix FTBFS with glibc >= 2.36. (LP #2015418)
      + d/p/fix-ftbfs-glibc-*.patch: Revert now-unnecessary
        upstream commits that were working around a glibc issue.
      [ Incorporated upstream. ]
    - d/qemu-system-x86.README.Debian: add info about updated nesting changes
      [ Debian linked the qemu-system-x86 documentation with the
        qemu-system-common package, rendering this README file not
        applicable. ]
    - d/p/u/allow-repeating-hot-unplug-requests.patch: Allow repeating
      hot-unplug requests by making ACPI PCI able to requeue them.
      (LP #2018733)
      [ Applied upstream. ]

 -- Sergio Durigan Junior <email address hidden>  Mon, 19 Jun 2023 15:45:09 -0400
Superseded in focal-updates
Superseded in focal-security
qemu (1:4.2-3ubuntu6.27) focal-security; urgency=medium

  * SECURITY UPDATE: user-after-free issue
    - debian/patches/CVE-2022-1050.patch: Protect against buggy or
      malicious guest driver
    - CVE-2022-1050
  * SECURITY UPDATE: Out-of-bounds read
    - debian/patches/CVE-2022-4144-*.patch: Have qxl_log_command Return
      early if no log_cmd handler; Document qxl_phys2virt(); Pass requested
      buffer size to qxl_phys2virt(); Avoid buffer overrun in qxl_phys2virt;
      Assert memory slot fits in preallocated MemoryRegion
    - CVE-2022-4144
  * SECURITY UPDATE: reentrancy problem
    - debian/patches/CVE-2023-0330.patch: Fix reentrancy issues in the LSI
      controller
    - CVE-2023-0330

 -- Nishit Majithia <email address hidden>  Tue, 13 Jun 2023 16:58:54 +0530
Superseded in jammy-updates
Superseded in jammy-security
qemu (1:6.2+dfsg-2ubuntu6.11) jammy-security; urgency=medium

  * SECURITY UPDATE: user-after-free issue
    - debian/patches/CVE-2022-1050.patch: Protect against buggy or
      malicious guest driver
    - CVE-2022-1050
  * SECURITY UPDATE: Out-of-bounds read
    - debian/patches/CVE-2022-4144-*.patch: Have qxl_log_command Return
      early if no log_cmd handler; Document qxl_phys2virt(); Pass requested
      buffer size to qxl_phys2virt(); Avoid buffer overrun in qxl_phys2virt;
      Assert memory slot fits in preallocated MemoryRegion
    - CVE-2022-4144
  * SECURITY UPDATE: reentrancy problem
    - debian/patches/CVE-2023-0330.patch: Fix reentrancy issues in the LSI
      controller
    - CVE-2023-0330

 -- Nishit Majithia <email address hidden>  Tue, 13 Jun 2023 17:03:25 +0530
Obsolete in kinetic-updates
Obsolete in kinetic-security
qemu (1:7.0+dfsg-7ubuntu2.6) kinetic-security; urgency=medium

  * SECURITY UPDATE: user-after-free issue
    - debian/patches/CVE-2022-1050.patch: Protect against buggy or
      malicious guest driver
    - CVE-2022-1050
  * SECURITY UPDATE: Out-of-bounds read
    - debian/patches/CVE-2022-4144-*.patch: Have qxl_log_command Return
      early if no log_cmd handler; Document qxl_phys2virt(); Pass requested
      buffer size to qxl_phys2virt(); Avoid buffer overrun in qxl_phys2virt;
      Assert memory slot fits in preallocated MemoryRegion
    - CVE-2022-4144
  * SECURITY UPDATE: integer and buffer overflow issue
    - debian/patches/CVE-2022-4172.patch: Fix memory handling issues
    - CVE-2022-4172
  * SECURITY UPDATE: reentrancy problem
    - debian/patches/CVE-2023-0330.patch: Fix reentrancy issues in the LSI
      controller
    - CVE-2023-0330

 -- Nishit Majithia <email address hidden>  Tue, 13 Jun 2023 17:04:15 +0530
Superseded in lunar-updates
Superseded in lunar-security
qemu (1:7.2+dfsg-5ubuntu2.2) lunar-security; urgency=medium

  * SECURITY UPDATE: reentrancy problem
    - debian/patches/CVE-2023-0330.patch: Fix reentrancy issues in the LSI
      controller
    - CVE-2023-0330

 -- Nishit Majithia <email address hidden>  Tue, 13 Jun 2023 17:07:25 +0530
Superseded in lunar-updates
Deleted in lunar-proposed (Reason: moved to -updates)
qemu (1:7.2+dfsg-5ubuntu2.1) lunar; urgency=medium

  * d/p/u/allow-repeating-hot-unplug-requests.patch: Allow repeating
    hot-unplug requests by making ACPI PCI able to requeue them.
    (LP: #2018733)

 -- Sergio Durigan Junior <email address hidden>  Fri, 26 May 2023 15:57:03 -0400
Superseded in kinetic-updates
Deleted in kinetic-proposed (Reason: moved to -updates)
qemu (1:7.0+dfsg-7ubuntu2.5) kinetic; urgency=medium

  * d/p/u/allow-repeating-hot-unplug-requests.patch: Allow repeating
    hot-unplug requests by making ACPI PCI able to requeue them.
    (LP: #2018733)

 -- Sergio Durigan Junior <email address hidden>  Fri, 26 May 2023 17:38:19 -0400
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.10) jammy; urgency=medium

  * d/p/u/allow-repeating-hot-unplug-requests.patch: Allow repeating
    hot-unplug requests by making ACPI PCI able to requeue them.
    (LP: #2018733)

 -- Sergio Durigan Junior <email address hidden>  Fri, 26 May 2023 17:40:31 -0400
Superseded in mantic-release
Deleted in mantic-proposed (Reason: Moved to mantic)
qemu (1:7.2+dfsg-5ubuntu3) mantic; urgency=medium

  * d/p/u/allow-repeating-hot-unplug-requests.patch: Allow repeating
    hot-unplug requests by making ACPI PCI able to requeue them.
    (LP: #2018733)

 -- Sergio Durigan Junior <email address hidden>  Thu, 18 May 2023 15:13:14 -0400
Superseded in jammy-updates
Superseded in jammy-proposed
qemu (1:6.2+dfsg-2ubuntu6.9) jammy; urgency=medium

  * d/p/u/lp-2019766-target-arm-kvm-Retry-KVM_CREATE_VM-call-if-it-fails-.patch:
    ARM: Retry KVM_CREATE_VM when it returns EINTR (LP: #2019766)

 -- dann frazier <email address hidden>  Tue, 16 May 2023 14:59:54 -0600
Superseded in kinetic-updates
Superseded in kinetic-proposed
qemu (1:7.0+dfsg-7ubuntu2.4) kinetic; urgency=medium

  * d/p/u/lp-2019766-target-arm-kvm-Retry-KVM_CREATE_VM-call-if-it-fails-.patch:
    ARM: Retry KVM_CREATE_VM when it returns EINTR (LP: #2019766)

 -- dann frazier <email address hidden>  Tue, 16 May 2023 14:59:50 -0600
Superseded in kinetic-updates
Deleted in kinetic-proposed (Reason: moved to -updates)
qemu (1:7.0+dfsg-7ubuntu2.3) kinetic; urgency=medium

  * d/p/u/lp-1999885-s390x-tod-kvm-don-t-save-restore-the-TOD-in-PV-guest.patch:
    avoid timer issues in s390x secure execution guests (LP: #1999885)
  * d/p/u/lp-2011832-*: fix emulation issues in mips (LP: #2011832)

 -- Christian Ehrhardt <email address hidden>  Thu, 23 Mar 2023 08:18:28 +0100
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.8) jammy; urgency=medium

  * d/p/u/lp-1999885-s390x-tod-kvm-don-t-save-restore-the-TOD-in-PV-guest.patch:
    avoid timer issues in s390x secure execution guests (LP: #1999885)
  * d/p/u/lp-2011832-*: fix emulation issues in mips and powerpc (LP: #2011832)

 -- Christian Ehrhardt <email address hidden>  Thu, 23 Mar 2023 08:18:28 +0100
Superseded in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
qemu (1:4.2-3ubuntu6.26) focal; urgency=medium

  * d/p/u/lp-1999885-s390x-tod-kvm-don-t-save-restore-the-TOD-in-PV-guest.patch:
    avoid timer issues in s390x secure execution guests (LP: #1999885)

 -- Christian Ehrhardt <email address hidden>  Thu, 23 Mar 2023 08:18:28 +0100
Superseded in mantic-release
Published in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
qemu (1:7.2+dfsg-5ubuntu2) lunar; urgency=medium

  * Fix FTBFS with glibc >= 2.36. (LP: #2015418)
    - d/p/fix-ftbfs-glibc-*.patch: Revert now-unnecessary
      upstream commits that were working around a glibc issue.

 -- Sergio Durigan Junior <email address hidden>  Wed, 05 Apr 2023 20:10:13 -0400
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
qemu (1:7.2+dfsg-5ubuntu1) lunar; urgency=medium

  * Re-merge with Debian unstable to pick up stabilization fixes
    remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP: 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - d/qemu-system-x86.NEWS Info on fixed machine type defintions
        for host-phys-bits=true
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP: 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - d/qemu-system-x86.README.Debian: add info about updated nesting changes
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - d/control-in: switch qemu-system-x86-xen to qemu-system-xen as this
      landed in Debian but under a different name.
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
    - d/control-in: libnfs is in main since focal, enable direct nfs
      storage support (LP 1988704)
    - d/control-in: libsndio is in universe in ubuntu

Published in bionic-updates
Deleted in bionic-proposed (Reason: moved to -updates)
qemu (1:2.11+dfsg-1ubuntu7.42) bionic; urgency=medium

  [ Brett Milford ]
  * d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
    error 'migration was active, but no RAM info was set' (LP: #1994002)

  [ Mauricio Faria de Oliveira ]
  * d/p/u/lp2009048-vfio_map_dma_einval_amd_iommu_1tb.patch: Add hint
    to VFIO_MAP_DMA error on AMD IOMMU for VMs with ~1TB+ RAM (LP: #2009048)

 -- Mauricio Faria de Oliveira <email address hidden>  Thu, 02 Mar 2023 18:26:12 -0300
Superseded in focal-updates
Deleted in focal-proposed (Reason: moved to -updates)
qemu (1:4.2-3ubuntu6.25) focal; urgency=medium

  [ Brett Milford ]
  * d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
    error 'migration was active, but no RAM info was set' (LP: #1994002)

  [ Mauricio Faria de Oliveira ]
  * d/p/u/lp2009048-vfio_map_dma_einval_amd_iommu_1tb.patch: Add hint
    to VFIO_MAP_DMA error on AMD IOMMU for VMs with ~1TB+ RAM (LP: #2009048)

 -- Mauricio Faria de Oliveira <email address hidden>  Thu, 02 Mar 2023 18:07:21 -0300
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.7) jammy; urgency=medium

  [ Brett Milford ]
  * d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
    error 'migration was active, but no RAM info was set' (LP: #1994002)

  [ Mauricio Faria de Oliveira ]
  * d/p/u/lp2009048-vfio_map_dma_einval_amd_iommu_1tb.patch: Add hint
    to VFIO_MAP_DMA error on AMD IOMMU for VMs with ~1TB+ RAM (LP: #2009048)
  * d/rules: move "Disable LTO on non-amd64" before buildflags.mk on Jammy.

  [ Michal Maloszewski ]
  * d/rules: Disable LTO on non-amd 64 architectures to prevent QEMU
    coroutines from failing (LP: #1921664)

 -- Mauricio Faria de Oliveira <email address hidden>  Mon, 06 Mar 2023 17:00:46 -0300
Superseded in kinetic-updates
Deleted in kinetic-proposed (Reason: moved to -updates)
qemu (1:7.0+dfsg-7ubuntu2.2) kinetic; urgency=medium

  [ Brett Milford ]
  * d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
    error 'migration was active, but no RAM info was set' (LP: #1994002)

  [ Mauricio Faria de Oliveira ]
  * d/p/u/lp2009048-vfio_map_dma_einval_amd_iommu_1tb.patch: Add hint
    to VFIO_MAP_DMA error on AMD IOMMU for VMs with ~1TB+ RAM (LP: #2009048)

 -- Mauricio Faria de Oliveira <email address hidden>  Thu, 02 Mar 2023 17:29:05 -0300
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
qemu (1:7.2+dfsg-4ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable (LP: #1993438), among many other fixes
    this resolvs these bugs:
    (LP: #1957924) - support for querying stats,
    (LP: #1853307) - Enhanced Interpretation for PCI Functions (s390x)
    (LP: #1959966) - guest dump encryption with customer keys (s390x)
    (LP: #1999885) - pv: don't allow userspace to set the clock under PV
    (LP: #1957924) - add filtering of statistics by target vCPU
    remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP: 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - d/qemu-system-x86.NEWS Info on fixed machine type defintions
        for host-phys-bits=true
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP: 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - d/qemu-system-x86.README.Debian: add info about updated nesting changes
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - d/control-in: switch qemu-system-x86-xen to qemu-system-xen as this
      landed in Debian but under a different name.
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
  * Dropped Changes [now part of upstream v7.2.0]
    - d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
      error 'migration was active, but no RAM info was set' (LP 1994002)
    - d/p/u/ebpf-replace-deprecated-bpf_program__set_socket_filt.patch:
      Fix FTBFS with libbpf 1.0.1-2.
      + Header updates that were added as part of the libbpf fixes
        but not mentioned in changelog
    - d/p/u/lp-1981339-*: fix s390x system emulation (LP 1981339)
    - Fix I/O stalls when using NVMe storage (LP 1970737).
      + d/p/lp1970737-linux-aio-*.patch: Fix unbalanced plugged counter
        in laio_io_unplug.
    - SECURITY UPDATE: heap overflow in floppy disk emulator
      + debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
        hw/block/fdc.c.
    - SECURITY UPDATE: use-after-free vulnerability
      + debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
        lsi_do_msgout
    - SECURITY UPDATE: heap overflow vulnerability
      + debian/patches/CVE-2022-2962.patch: tulip: Restrict DMA engine to
        memories
    - SECURITY UPDATE: integer underflow vulnerability
      + debian/patches/CVE-2022-3165.patch: fix integer underflow in
        vnc_client_cut_text_ext
  * Dropped Changes in regard to GCC-12 FTBFS (LP 1988710)
    [not all are needed in lunar]
    -  d/p/u/lp1988710-silence-openbios-array-bounds-false-positive.patch.
       Silence -Warray-bounds false positive [no more needed]
    - d/rules: set -O1 for alpha firmware build
    - d/p/u/lp1988710-opensbi-Makefile-fix-build-with-binutils-2.38.patch:
      further FTBFS fixup
  * Dropped Changes [in Debian 1:7.2+dfsg-3]
    - d/rules: disable LTO on non-amd64 builds (LP 1921664)
  * Added Changes
    - d/control-in: libnfs is in main since focal, enable direct nfs
      storage support (LP: #1988704)
    - d/control-in: libsndio is in universe in ubuntu

Superseded in lunar-proposed
qemu (1:7.2+dfsg-3ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable (LP: #1993438), among many other fixes
    this resolvs these bugs:
    (LP: #1957924) - support for querying stats,
    (LP: #1853307) - Enhanced Interpretation for PCI Functions (s390x)
    (LP: #1959966) - guest dump encryption with customer keys (s390x)
    (LP: #1999885) - pv: don't allow userspace to set the clock under PV
    (LP: #1957924) - add filtering of statistics by target vCPU
    remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP: 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - d/qemu-system-x86.NEWS Info on fixed machine type defintions
        for host-phys-bits=true
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP: 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - d/qemu-system-x86.README.Debian: add info about updated nesting changes
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - d/control-in: switch qemu-system-x86-xen to qemu-system-xen as this
      landed in Debian but under a different name.
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
  * Dropped Changes [now part of upstream v7.2.0]
    - d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
      error 'migration was active, but no RAM info was set' (LP 1994002)
    - d/p/u/ebpf-replace-deprecated-bpf_program__set_socket_filt.patch:
      Fix FTBFS with libbpf 1.0.1-2.
      + Header updates that were added as part of the libbpf fixes
        but not mentioned in changelog
    - d/p/u/lp-1981339-*: fix s390x system emulation (LP 1981339)
    - Fix I/O stalls when using NVMe storage (LP 1970737).
      + d/p/lp1970737-linux-aio-*.patch: Fix unbalanced plugged counter
        in laio_io_unplug.
    - SECURITY UPDATE: heap overflow in floppy disk emulator
      + debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
        hw/block/fdc.c.
    - SECURITY UPDATE: use-after-free vulnerability
      + debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
        lsi_do_msgout
    - SECURITY UPDATE: heap overflow vulnerability
      + debian/patches/CVE-2022-2962.patch: tulip: Restrict DMA engine to
        memories
    - SECURITY UPDATE: integer underflow vulnerability
      + debian/patches/CVE-2022-3165.patch: fix integer underflow in
        vnc_client_cut_text_ext
  * Dropped Changes in regard to GCC-12 FTBFS (LP 1988710)
    [not all are needed in lunar]
    -  d/p/u/lp1988710-silence-openbios-array-bounds-false-positive.patch.
       Silence -Warray-bounds false positive [no more needed]
    - d/rules: set -O1 for alpha firmware build
    - d/p/u/lp1988710-opensbi-Makefile-fix-build-with-binutils-2.38.patch:
      further FTBFS fixup
  * Dropped Changes [in Debian 1:7.2+dfsg-3]
    - d/rules: disable LTO on non-amd64 builds (LP 1921664)
  * Added Changes
    - d/control-in: libnfs is in main since focal, enable direct nfs
      storage support (LP: #1988704)
    - d/control-in: libsndio is in universe in ubuntu

Superseded in lunar-proposed
qemu (1:7.2+dfsg-2ubuntu1) lunar; urgency=medium

  * Merge with Debian unstable (LP: #1993438), among many other fixes
    this resolvs these bugs:
    (LP: #1957924) - support for querying stats,
    (LP: #1853307) - Enhanced Interpretation for PCI Functions (s390x)
    (LP: #1959966) - guest dump encryption with customer keys (s390x)
    (LP: #1999885) - pv: don't allow userspace to set the clock under PV
    (LP: #1957924) - add filtering of statistics by target vCPU
    remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP: 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - d/qemu-system-x86.NEWS Info on fixed machine type defintions
        for host-phys-bits=true
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP: 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - d/qemu-system-x86.README.Debian: add info about updated nesting changes
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - d/control-in: switch qemu-system-x86-xen to qemu-system-xen as this
      landed in Debian but under a different name.
    - Remaining GCC-12 FTBFS (LP 1988710 + LP 1921664)
      + d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch:
        fix qboot FTBFS with LTO
      + d/rules: disable LTO on non-amd64 builds (LP 1921664)
  * Dropped Changes [now part of upstream v7.2.0]
    - d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
      error 'migration was active, but no RAM info was set' (LP 1994002)
    - d/p/u/ebpf-replace-deprecated-bpf_program__set_socket_filt.patch:
      Fix FTBFS with libbpf 1.0.1-2.
      + Header updates that were added as part of the libbpf fixes
        but not mentioned in changelog
    - d/p/u/lp-1981339-*: fix s390x system emulation (LP 1981339)
    - Fix I/O stalls when using NVMe storage (LP 1970737).
      + d/p/lp1970737-linux-aio-*.patch: Fix unbalanced plugged counter
        in laio_io_unplug.
    - SECURITY UPDATE: heap overflow in floppy disk emulator
      + debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
        hw/block/fdc.c.
    - SECURITY UPDATE: use-after-free vulnerability
      + debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
        lsi_do_msgout
    - SECURITY UPDATE: heap overflow vulnerability
      + debian/patches/CVE-2022-2962.patch: tulip: Restrict DMA engine to
        memories
    - SECURITY UPDATE: integer underflow vulnerability
      + debian/patches/CVE-2022-3165.patch: fix integer underflow in
        vnc_client_cut_text_ext
  * Dropped Changes in regard to GCC-12 FTBFS (LP 1988710)
    [not all are needed in lunar]
    -  d/p/u/lp1988710-silence-openbios-array-bounds-false-positive.patch.
       Silence -Warray-bounds false positive [no more needed]
    - d/rules: set -O1 for alpha firmware build
    - d/p/u/lp1988710-opensbi-Makefile-fix-build-with-binutils-2.38.patch:
      further FTBFS fixup
  * Added Changes
    - d/control-in: libnfs is in main since focal, enable direct nfs
      storage support (LP: #1988704)

 -- Christian Ehrhardt <email address hidden>  Wed, 04 Jan 2023 13:18:43 +0100
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
qemu (1:7.0+dfsg-7ubuntu4) lunar; urgency=medium

  * SECURITY UPDATE: use-after-free vulnerability
    - debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
      lsi_do_msgout
    - CVE-2022-0216
  * SECURITY UPDATE: heap overflow vulnerability
    - debian/patches/CVE-2022-2962.patch: tulip: Restrict DMA engine to
      memories
    - CVE-2022-2962
  * SECURITY UPDATE: integer underflow vulnerability
    - debian/patches/CVE-2022-3165.patch: fix integer underflow in
      vnc_client_cut_text_ext
    - CVE-2022-3165

 -- Nishit Majithia <email address hidden>  Fri, 09 Dec 2022 10:25:52 +0530
Superseded in kinetic-updates
Superseded in kinetic-security
qemu (1:7.0+dfsg-7ubuntu2.1) kinetic-security; urgency=medium

  * SECURITY UPDATE: use-after-free vulnerability
    - debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
      lsi_do_msgout
    - CVE-2022-0216
  * SECURITY UPDATE: heap overflow vulnerability
    - debian/patches/CVE-2022-2962.patch: tulip: Restrict DMA engine to
      memories
    - CVE-2022-2962
  * SECURITY UPDATE: integer underflow vulnerability
    - debian/patches/CVE-2022-3165.patch: fix integer underflow in
      vnc_client_cut_text_ext
    - CVE-2022-3165

 -- Nishit Majithia <email address hidden>  Thu, 08 Dec 2022 14:52:29 +0530
Superseded in jammy-updates
Superseded in jammy-security
qemu (1:6.2+dfsg-2ubuntu6.6) jammy-security; urgency=medium

  * SECURITY UPDATE: DMA reentrancy issue
    - debian/patches/CVE-2021-3750.patch: Introduce MemTxAttrs::memory
      field and MEMTX_ACCESS_ERROR
    - CVE-2021-3750
  * SECURITY UPDATE: use-after-free vulnerability
    - debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
      lsi_do_msgout
    - CVE-2022-0216
  * SECURITY UPDATE: integer underflow vulnerability
    - debian/patches/CVE-2022-3165.patch: fix integer underflow in
      vnc_client_cut_text_ext
    - CVE-2022-3165

 -- Nishit Majithia <email address hidden>  Thu, 08 Dec 2022 14:47:27 +0530
Superseded in focal-updates
Superseded in focal-security
qemu (1:4.2-3ubuntu6.24) focal-security; urgency=medium

  * SECURITY UPDATE: DMA reentrancy issue
    - debian/patches/CVE-2021-3750.patch: Introduce MemTxAttrs::memory
      field and MEMTX_ACCESS_ERROR
    - CVE-2021-3750
  * SECURITY UPDATE: use-after-free vulnerability
    - debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
      lsi_do_msgout
    - CVE-2022-0216

 -- Nishit Majithia <email address hidden>  Thu, 08 Dec 2022 14:45:56 +0530
Superseded in bionic-updates
Published in bionic-security
qemu (1:2.11+dfsg-1ubuntu7.41) bionic-security; urgency=medium

  * SECURITY UPDATE: DMA reentrancy issue
    - debian/patches/CVE-2021-3750.patch: Introduce MemTxAttrs::memory
      field and MEMTX_ACCESS_ERROR
    - CVE-2021-3750
  * SECURITY UPDATE: use-after-free vulnerability
    - debian/patches/CVE-2022-0216-*.patch: fix use-after-free in
      lsi_do_msgout
    - CVE-2022-0216

 -- Nishit Majithia <email address hidden>  Thu, 08 Dec 2022 14:38:49 +0530
Superseded in lunar-release
Deleted in lunar-proposed (Reason: Moved to lunar)
qemu (1:7.0+dfsg-7ubuntu3) lunar; urgency=medium

  [ Brett Milford ]
  * d/p/u/lp1994002-migration-Read-state-once.patch: Fix for libvirt
    error 'migration was active, but no RAM info was set' (LP: #1994002)

  [ Mauricio Faria de Oliveira ]
  * d/p/u/ebpf-replace-deprecated-bpf_program__set_socket_filt.patch:
    Fix FTBFS with libbpf 1.0.1-2.

 -- Mauricio Faria de Oliveira <email address hidden>  Wed, 30 Nov 2022 12:17:51 -0300
Superseded in lunar-release
Obsolete in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
qemu (1:7.0+dfsg-7ubuntu2) kinetic; urgency=medium

  [ Paride Legovini ]
  * d/rules: disable LTO on non-amd64 builds (LP: #1921664)
  * GCC-12 FTBFS (LP: #1988710)
    - d/p/u/lp1988710-silence-openbios-array-bounds-false-positive.patch.
      Silence -Warray-bounds false positive (treated as error)

  [ Christian Ehrhardt ]
  * More on GCC-12 FTBFS (LP 1988710)
    - d/rules: set -O1 for alpha firmware build
    - d/p/u/lp1988710-opensbi-Makefile-fix-build-with-binutils-2.38.patch:
      further FTBFS fixup

 -- Christian Ehrhardt <email address hidden>  Mon, 19 Sep 2022 08:07:24 +0200
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.5) jammy; urgency=medium

  * d/p/u/lp-1981339-*: Fix s390x emulation of newer kernels (LP: #1981339)

 -- Christian Ehrhardt <email address hidden>  Tue, 13 Sep 2022 10:23:19 +0200
Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.4) jammy; urgency=medium

  * Fix ppc64le: fatal: Tried to call a TRAP (LP: #1980896)
    - linux-user/ppc: Use force_sig_fault
    - linux-user/ppc: deliver SIGTRAP on POWERPC_EXCP_TRAP
    - tests/tcg/ppc64le: change signal_save_restore_xer to use SIGTRAP

 -- You-Sheng Yang <email address hidden>  Thu, 07 Jul 2022 02:52:56 +0000
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
qemu (1:7.0+dfsg-7ubuntu1) kinetic; urgency=medium

  * Merge with Debian unstable (LP: #1971315)(LP: #1980896), remaining changes:
    - qemu-kvm to systemd unit
      - d/qemu-kvm-init: script for QEMU KVM preparation modules, ksm,
        hugepages and architecture specifics
      - d/qemu-system-common.qemu-kvm.service: systemd unit to call
        qemu-kvm-init
      - d/qemu-system-common.install: install helper script
      - d/qemu-system-common.qemu-kvm.default: defaults for
        /etc/default/qemu-kvm
      - d/rules: call dh_installinit and dh_installsystemd for qemu-kvm
    - Distribution specific machine type
      (LP: 1304107 1621042 1776189 1761372 1761372 1776189)
      - d/p/ubuntu/define-ubuntu-machine-types.patch: define distro machine
        types containing release versioned machine attributes
      - d/qemu-system-x86.NEWS Info on fixed machine type defintions
        for host-phys-bits=true
      - Add an info about -hpb machine type in debian/qemu-system-x86.NEWS
      - ubuntu-q35 alias added to auto-select the most recent q35 ubuntu type
    - Enable nesting by default
      - d/p/ubuntu/enable-svm-by-default.patch: Enable nested svm by default
        in qemu64 on amd
        [ No more strictly needed, but required for backward compatibility ]
    - tolerate ipxe size change on migrations to >=18.04 (LP: 1713490)
      - d/p/ubuntu/pre-bionic-256k-ipxe-efi-roms.patch: old machine types
        reference 256k path
      - d/control-in: depend on ipxe-qemu-256k-compat-efi-roms to be able to
        handle incoming migrations from former releases.
    - d/qemu-system-x86.README.Debian: add info about updated nesting changes
    - Ease the use of module retention on upgrades (LP 1913421)
      - debian/qemu-block-extra.postinst: enable mount unit on install/upgrade
    - Fix I/O stalls when using NVMe storage (LP 1970737).
      - d/p/lp1970737-linux-aio-*.patch: Fix unbalanced plugged counter
        in laio_io_unplug.
    - SECURITY UPDATE: heap overflow in floppy disk emulator
      - debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
        hw/block/fdc.c.
      - CVE-2021-3507
  * Dropped Changes [now part of 1:7.0+dfsg-7]:
    - d/rules: xen libexec dir is no more versioned
    - d/rules: ensure xen is built on x86
    - d/kvm-spice: fix when acceleration is already defined on the commandline
    - debian/control[-in]: no more disable glusterfs in Ubuntu (LP 1246924)
  * Dropped Changes [now part of upstream v7.0.0]
    - d/p/u/lp-1959984-s390x-ipl-support-extended-kernel-command-line-size.patch
      Allow long kernel command lines for QEMU (LP 1959984)
    - d/p/u/fix-virtiofsd-for-glibc2.35.patch: add rseq to seccomp allow list
    - d/p/u/tcg-Remove-dh_alias-indirection-for-dh_typecode.patch: fix 32bit
      tcg on s390x.
    - Fix diff handling on ceph that can cause data corruption (LP 1968258)
      - d/p/u/lp-1968258-block-rbd-fix-handling-of-holes-in-.bdrv_co.patch
      - d/p/u/lp-1968258-block-rbd-workaround-for-ceph-issue-53784.patch
    - d/p/u/lp-1970563-ui-vnc.c-Fixed-a-deadlock-bug.patch: avoid deadlock
      in vnc connections (LP 1970563)
    - All CVE fixes of 1:6.2+dfsg-2ubuntu8 except CVE-2021-3507
  * Dropped Changes
    - d/p/lp-1952448-relax-skiboot-gcc-deprecation-errors.patch:
      add patch to workaround FTBFS when building against OpenSSL 3.0.
      [ now working with OpenSSL 3.0 ]
    - d/optionrom.mak, d/p/u/avoid-fcf-clashing-with-i486.patch: fix
      -fcf-protection being unavailble on -march=i486 (LP 1940029)
      [ fixed in compiler toolchain ]
    - Make qemu-system-x86-microvm a transitional package as the binary is now
      in qemu-system-x86 itself.
      [ no more needed]
  * Added Changes
    - d/control-in: switch qemu-system-x86-xen to qemu-system-xen as this
      landed in Debian but under a different name.
    - d/p/u/qboot-Disable-LTO-for-ELF-binary-build-step.patch: fix qboot FTBFS
      with LTO
    - d/p/u/lp-1981339-*: fix s390x system emulation (LP: #1981339)

Superseded in jammy-updates
Deleted in jammy-proposed (Reason: moved to -updates)
qemu (1:6.2+dfsg-2ubuntu6.3) jammy; urgency=medium

  * Fix unbalanced plugged counter in laio_io_unplug (LP: #1970737)
    - d/p/lp1970737-linux-aio-*.patch: Upstream patches.

 -- Sergio Durigan Junior <email address hidden>  Tue, 21 Jun 2022 17:07:50 -0400
Superseded in kinetic-release
Deleted in kinetic-proposed (Reason: Moved to kinetic)
qemu (1:6.2+dfsg-2ubuntu8) kinetic; urgency=medium

  [ Marc Deslauriers ]
  * SECURITY UPDATE: heap overflow in floppy disk emulator
    - debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
      hw/block/fdc.c.
    - CVE-2021-3507
  * SECURITY UPDATE: use-after-free in nvme
    - debian/patches/CVE-2021-3929.patch: deny DMA to the iomem of the
      device itself in hw/nvme/ctrl.c.
    - CVE-2021-3929
  * SECURITY UPDATE: integer overflow in QXL display device emulation
    - debian/patches/CVE-2021-4206.patch: check width and height in
      hw/display/qxl-render.c, hw/display/vmware_vga.c, ui/cursor.c.
    - CVE-2021-4206
  * SECURITY UPDATE: heap overflow in QXL display device emulation
    - debian/patches/CVE-2021-4207.patch: fix race condition in qxl_cursor
      in hw/display/qxl-render.c.
    - CVE-2021-4207
  * SECURITY UPDATE: potential privilege escalation in virtiofsd
    - debian/patches/CVE-2022-0358.patch: Drop membership of all
      supplementary groups in tools/virtiofsd/passthrough_ll.c.
    - CVE-2022-0358
  * SECURITY UPDATE: memory leakage in virtio-net device
    - debian/patches/CVE-2022-26353.patch: fix map leaking on error during
      receive in hw/net/virtio-net.c.
    - CVE-2022-26353
  * SECURITY UPDATE: memory leakage in vhost-vsock device
    - debian/patches/CVE-2022-26354.patch: detach the virqueue element in
      case of error in hw/virtio/vhost-vsock-common.c.
    - CVE-2022-26354

  [ Sergio Durigan Junior ]
  * Fix I/O stalls when using NVMe storage (LP: #1970737).
    - d/p/lp1970737-linux-aio-*.patch: Fix unbalanced plugged counter
      in laio_io_unplug.

 -- Sergio Durigan Junior <email address hidden>  Wed, 22 Jun 2022 15:38:37 -0400
Superseded in bionic-updates
Superseded in bionic-security
qemu (1:2.11+dfsg-1ubuntu7.40) bionic-security; urgency=medium

  * SECURITY UPDATE: heap overflow in floppy disk emulator
    - debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
      hw/block/fdc.c.
    - CVE-2021-3507
  * SECURITY UPDATE: integer overflow in QXL display device emulation
    - debian/patches/CVE-2021-4206.patch: check width and height in
      hw/display/qxl-render.c, hw/display/vmware_vga.c, ui/cursor.c.
    - CVE-2021-4206
  * SECURITY UPDATE: heap overflow in QXL display device emulation
    - debian/patches/CVE-2021-4207.patch: fix race condition in qxl_cursor
      in hw/display/qxl-render.c.
    - CVE-2021-4207
  * SECURITY UPDATE: memory leakage in virtio-net device
    - debian/patches/CVE-2022-26353.patch: fix map leaking on error during
      receive in hw/net/virtio-net.c.
    - CVE-2022-26353
  * SECURITY UPDATE: memory leakage in vhost-vsock device
    - debian/patches/CVE-2022-26354.patch: detach the virqueue element in
      case of error in hw/virtio/vhost-vsock.c.
    - CVE-2022-26354

 -- Marc Deslauriers <email address hidden>  Thu, 09 Jun 2022 11:37:25 -0400
Obsolete in impish-updates
Obsolete in impish-security
qemu (1:6.0+dfsg-2expubuntu1.3) impish-security; urgency=medium

  * SECURITY UPDATE: heap overflow in floppy disk emulator
    - debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
      hw/block/fdc.c.
    - CVE-2021-3507
  * SECURITY UPDATE: integer overflow in QXL display device emulation
    - debian/patches/CVE-2021-4206.patch: check width and height in
      hw/display/qxl-render.c, hw/display/vmware_vga.c, ui/cursor.c.
    - CVE-2021-4206
  * SECURITY UPDATE: heap overflow in QXL display device emulation
    - debian/patches/CVE-2021-4207.patch: fix race condition in qxl_cursor
      in hw/display/qxl-render.c.
    - CVE-2021-4207
  * SECURITY UPDATE: memory leakage in virtio-net device
    - debian/patches/CVE-2022-26353.patch: fix map leaking on error during
      receive in hw/net/virtio-net.c.
    - CVE-2022-26353
  * SECURITY UPDATE: memory leakage in vhost-vsock device
    - debian/patches/CVE-2022-26354.patch: detach the virqueue element in
      case of error in hw/virtio/vhost-vsock-common.c.
    - CVE-2022-26354

 -- Marc Deslauriers <email address hidden>  Thu, 09 Jun 2022 11:30:03 -0400
Superseded in jammy-updates
Superseded in jammy-security
qemu (1:6.2+dfsg-2ubuntu6.2) jammy-security; urgency=medium

  * SECURITY UPDATE: heap overflow in floppy disk emulator
    - debian/patches/CVE-2021-3507.patch: prevent end-of-track overrun in
      hw/block/fdc.c.
    - CVE-2021-3507
  * SECURITY UPDATE: use-after-free in nvme
    - debian/patches/CVE-2021-3929.patch: deny DMA to the iomem of the
      device itself in hw/nvme/ctrl.c.
    - CVE-2021-3929
  * SECURITY UPDATE: integer overflow in QXL display device emulation
    - debian/patches/CVE-2021-4206.patch: check width and height in
      hw/display/qxl-render.c, hw/display/vmware_vga.c, ui/cursor.c.
    - CVE-2021-4206
  * SECURITY UPDATE: heap overflow in QXL display device emulation
    - debian/patches/CVE-2021-4207.patch: fix race condition in qxl_cursor
      in hw/display/qxl-render.c.
    - CVE-2021-4207
  * SECURITY UPDATE: potential privilege escalation in virtiofsd
    - debian/patches/CVE-2022-0358.patch: Drop membership of all
      supplementary groups in tools/virtiofsd/passthrough_ll.c.
    - CVE-2022-0358
  * SECURITY UPDATE: memory leakage in virtio-net device
    - debian/patches/CVE-2022-26353.patch: fix map leaking on error during
      receive in hw/net/virtio-net.c.
    - CVE-2022-26353
  * SECURITY UPDATE: memory leakage in vhost-vsock device
    - debian/patches/CVE-2022-26354.patch: detach the virqueue element in
      case of error in hw/virtio/vhost-vsock-common.c.
    - CVE-2022-26354

 -- Marc Deslauriers <email address hidden>  Thu, 09 Jun 2022 11:22:05 -0400
175 of 566 results