]> git.proxmox.com Git - pve-qemu-kvm.git/blobdiff - debian/changelog
disable fix for CVE-2016-3712 (do not compile)
[pve-qemu-kvm.git] / debian / changelog
index 1139a6785ad12d7898dd0010dda5e5320be02fe3..5f42069b2beb66a0bc783ba3350401161f5c5a7f 100644 (file)
@@ -1,3 +1,279 @@
+pve-qemu-kvm (2.2-26) unstable; urgency=low
+
+  * fix CVE-2016-4037
+   ehci: apply limit to iTD/sidt descriptors
+
+   * fix CVE-2016-4453
+   vmsvga: don't process more than 1024 fifo commands at once
+
+   * fix CVE-2016-4454
+   vmsvga: move fifo sanity checks to vmsvga_fifo_length
+   vmsvga: add more fifo checks
+   vmsvga: shadow fifo registers
+
+   * fix CVE-2016-4952
+   scsi: pvscsi: check command descriptor ring buffer size
+
+   * fix CVE-2016-5105
+   scsi: megasas: initialise local configuration data buffer
+
+   * fix CVE-2016-5106
+   scsi: megasas: use appropriate property buffer size
+
+   * fix CVE-2016-5107
+   scsi: megasas: check 'read_queue_head' index value
+
+   * fix CVE-2016-5126
+   block/iscsi: avoid potential overflow of acb->task->cdb
+
+   * CVE-2016-6490
+   virtio: check vring descriptor buffer length
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 05 Aug 2016 11:50:29 +0200
+
+pve-qemu-kvm (2.2-25) unstable; urgency=low
+
+  * Fix CVE-2016-2841, CVE-2016-2857, CVE-2016-2858
+
+ -- Proxmox Support Team <support@proxmox.com>  Mon, 07 Mar 2016 17:14:14 +0100
+
+pve-qemu-kvm (2.2-24) unstable; urgency=low
+
+  * Fix CVE-2015-8817 and CVE-2015-8818
+
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 02 Mar 2016 16:42:16 +0100
+
+pve-qemu-kvm (2.2-23) unstable; urgency=low
+
+  * Fix CVE-2016-2538
+
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 24 Feb 2016 16:36:59 +0100
+
+pve-qemu-kvm (2.2-22) unstable; urgency=low
+
+  * Fix CVE-2016-2391 and CVE-2016-2392
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 18 Feb 2016 09:52:22 +0100
+
+pve-qemu-kvm (2.2-21) unstable; urgency=low
+
+  * fix CVE-2016-1568: ide: ahci: reset ncq object to unused on error
+
+  * fix CVE-2015-3209: pcnet: force the buffer access to be in bounds during tx
+
+  * fix CVE-2015-7504: net: pcnet: add check to validate receive data size
+
+  * fix CVE-2015-7512: pcnet: fix rx buffer overflow
+
+  * fix CVE-2015-7295
+
+ -- Proxmox Support Team <support@proxmox.com>  Tue, 09 Feb 2016 17:34:00 +0100
+
+pve-qemu-kvm (2.2-20) unstable; urgency=low
+
+  * Fix CVE-2016-1981
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 22 Jan 2016 09:25:17 +0100
+
+pve-qemu-kvm (2.2-19) unstable; urgency=low
+
+  * Fix CVE-2016-1922: i386: avoid null pointer dereference
+
+ -- Proxmox Support Team <support@proxmox.com>  Mon, 18 Jan 2016 11:06:14 +0100
+
+pve-qemu-kvm (2.2-18) unstable; urgency=low
+
+  * fix CVE-2016-1714 - fw_cfg oob r/w access
+
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 13 Jan 2016 10:58:09 +0100
+
+pve-qemu-kvm (2.2-17) unstable; urgency=low
+
+  * hmp: fix sendkey out of bounds write (CVE-2015-8619)
+
+ -- Proxmox Support Team <support@proxmox.com>  Mon, 11 Jan 2016 15:41:23 +0100
+
+pve-qemu-kvm (2.2-16) unstable; urgency=low
+
+  * Removing wrong CVE-2015-8619
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 08 Jan 2016 12:46:34 +0100
+
+pve-qemu-kvm (2.2-15) unstable; urgency=low
+
+  * CVE-2015-8613 scsi: initialise info object with appropriate size
+
+  * CVE-2015-8619 hmp: avoid redundant null termination of buffer
+
+  * CVE-2015-8666 acpi: fix buffer overrun on migration
+
+  * CVE-2015-8743 net: ne2000: fix bounds check in ioport operations
+
+  * CVE-2015-8744 net/vmxnet3: Refine l2 header validation
+
+  * CVE-2015-8745 vmxnet3: Support reading IMR registers on bar0
+
+  * fixes for CVEs 2015-7549, 2015-8858 and for vmxnet3
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 07 Jan 2016 12:17:13 +0100
+
+pve-qemu-kvm (2.2-14) unstable; urgency=low
+
+  * fix CVE-2015-8504
+
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 09 Dec 2015 12:37:47 +0100
+
+pve-qemu-kvm (2.2-13) unstable; urgency=low
+
+  * fix CVE-2015-1779
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 30 Oct 2015 09:50:10 +0100
+
+pve-qemu-kvm (2.2-12) unstable; urgency=low
+
+  * added ne2000 patch
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 22 Oct 2015 12:24:22 +0200
+
+pve-qemu-kvm (2.2-11) unstable; urgency=low
+
+  * fix CVE-2015-5154
+
+ -- Proxmox Support Team <support@proxmox.com>  Tue, 28 Jul 2015 07:08:39 +0200
+
+pve-qemu-kvm (2.2-10) unstable; urgency=low
+
+  * fix VENOM qemu security flaw (CVE-2015-3456)
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 14 May 2015 09:37:00 +0200
+
+pve-qemu-kvm (2.2-9) unstable; urgency=low
+
+  * fix assert while resizing or hot plugging virtio scsi disks
+
+ -- Proxmox Support Team <support@proxmox.com>  Tue, 31 Mar 2015 06:33:07 +0200
+
+pve-qemu-kvm (2.2-8) unstable; urgency=low
+
+  * update to v2.2.1
+  
+  * fix ballooning with memory hotplug
+  
+  * remove fix-mc146818rtc-wrong-subsection-name.patch (now upstream)
+  
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 11 Mar 2015 07:02:14 +0100
+
+pve-qemu-kvm (2.2-7) unstable; urgency=low
+
+  * fix mc146818rtc wrong subsection name to avoid
+    vmstate_subsection_load() fail.
+
+ -- Proxmox Support Team <support@proxmox.com>  Tue, 24 Feb 2015 17:38:31 +0100
+
+pve-qemu-kvm (2.2-6) unstable; urgency=low
+
+  * qmp: fix backup-cancel
+
+ -- Proxmox Support Team <support@proxmox.com>  Mon, 29 Dec 2014 07:21:24 +0100
+
+pve-qemu-kvm (2.2-5) unstable; urgency=low
+
+  * add new qmp command: get_link_status
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 11 Dec 2014 10:42:20 +0100
+
+pve-qemu-kvm (2.2-4) unstable; urgency=low
+
+  * update to qemu v2.2.0
+
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 10 Dec 2014 06:18:34 +0100
+
+pve-qemu-kvm (2.2-3) unstable; urgency=low
+
+  * update to qemu v2.2.0-rc5
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 05 Dec 2014 13:27:35 +0100
+
+pve-qemu-kvm (2.2-2) unstable; urgency=low
+
+  * update to qemu v2.2.0-rc3+ (commit 4cae4d5acaea23f3def84c8dc67ef5106323e5cb)
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 28 Nov 2014 11:50:25 +0100
+
+pve-qemu-kvm (2.2-1) unstable; urgency=low
+
+  * update to qemu v2.2.0-rc2
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 20 Nov 2014 07:56:27 +0100
+
+pve-qemu-kvm (2.1-10) unstable; urgency=low
+
+  * enable support for write_zeroes and discard for images on xfs filesystem
+
+ -- Proxmox Support Team <support@proxmox.com>  Mon, 13 Oct 2014 10:19:44 +0200
+
+pve-qemu-kvm (2.1-9) unstable; urgency=low
+
+  * update to v2.1.2
+  
+  * remove temporary patches (now upstream)
+    - virtio-net_drop_assert_on_vm_stop.patch
+    - revert_virtio_dont_call_device_on_not_vm_running.patch
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 26 Sep 2014 11:25:57 +0200
+
+pve-qemu-kvm (2.1-8) unstable; urgency=low
+
+  * apply patches/hotfix for virtio-net migration problem in 2.1.1
+    - virtio-net_drop_assert_on_vm_stop.patch
+    - revert_virtio_dont_call_device_on_not_vm_running.patch
+
+ -- Proxmox Support Team <support@proxmox.com>  Tue, 16 Sep 2014 12:54:48 +0200
+
+pve-qemu-kvm (2.1-7) unstable; urgency=low
+
+  * update to v2.1.1
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 11 Sep 2014 09:27:38 +0200
+
+pve-qemu-kvm (2.1-6) unstable; urgency=low
+
+  *  gluster: allow to specify a backup server
+
+ -- Proxmox Support Team <support@proxmox.com>  Tue, 26 Aug 2014 12:55:23 +0200
+
+pve-qemu-kvm (2.1-5) unstable; urgency=low
+
+  * glusterfs: do not log to stdout when daemonized
+
+ -- Proxmox Support Team <support@proxmox.com>  Fri, 22 Aug 2014 13:28:24 +0200
+
+pve-qemu-kvm (2.1-4) unstable; urgency=low
+
+  * depend on new libiscsi 1.12.0
+  
+  * depend on new glusterfs 3.5.2
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 21 Aug 2014 08:18:43 +0200
+
+pve-qemu-kvm (2.1-3) unstable; urgency=low
+
+  * snapshot: fix reference counting bug
+
+ -- Proxmox Support Team <support@proxmox.com>  Thu, 07 Aug 2014 13:31:30 +0200
+
+pve-qemu-kvm (2.1-2) unstable; urgency=low
+
+  * update to v2.1.0
+
+ -- Proxmox Support Team <support@proxmox.com>  Sat, 02 Aug 2014 15:00:58 +0200
+
+pve-qemu-kvm (2.1-1) unstable; urgency=low
+
+  * update to v2.1.0-rc2
+
+ -- Proxmox Support Team <support@proxmox.com>  Wed, 16 Jul 2014 11:55:13 +0200
+
 pve-qemu-kvm (2.0-2) unstable; urgency=low
 
   * update to latest qemu (commit 2a2c4830c0068d70443f3dddc4cc668f0c601b5c)