Hi! On Mon, Sep 09, 2019 at 06:35:37PM +0000, Mike Gabriel wrote: > On Mo 09 Sep 2019 11:23:59 CEST, Sylvain Beucler wrote: > > On 04/09/2019 15:41, Sylvain Beucler wrote: > > > We have a prepared QEMU update from 3 months ago that needs attention: > > > https://packages.sunweavers.net/debian/pool/main/q/qemu/ > > > > > > It fixes: > > > CVE-2017-9375 CVE-2019-12155 CVE-2017-15124 CVE-2016-5403 CVE-2016-5126 > > > > > > Since then we got: > > > CVE-2019-14378 CVE-2019-13164 CVE-2019-12068 CVE-2019-12067 > > > and possibly CVE-2018-19665 to reconsider. > > > > > > I can take the time to setup a physical box and provide more testing / > > > more patching. > > > Before doing so, I thought I'd first check: > > > what are you plans for this month regarding this update? :) > > Ping? > > Thanks for pinging. And: sorry, I did not get any work on this done on > Saturday. > > Did you get any testing work done on this already? If not, I'd suggest to > meet on IRC on Friday this week, after 10am (CEST) and get to work on this > together. Is that a plan? Let me know, if you are available then.
No extensive testing yet. I setup a physical Jessie machine (an AMD/svm, btw) and started triaging the pending issues. I plan to integrate more issues and prepare some tests (e.g. LVM so as to test partition disk images and possibly install an old ProxMox). I can make myself available on Friday 10AM, that sounds good. Cheers! Sylvain
