Hi, I'd like to dispute CVE-2024-26908: the issue fixed by upstream commit 3693bb4465e6e32a204a5b86d3ec7e6b9f7e67c2 can in no way be triggered by an unprivileged user or by a remote attack of the system, as it requires hotplug of (virtual) cpus to the running system. This can be done only by either a host admin or by an admin of the guest which might suffer the out-of-memory situation.
Please revoke this CVE. Juergen
OpenPGP_0xB0DE9DD628BF132F.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature