Skip to content

Fix QEMU CVEs#713

Merged
andy-vm merged 1 commit intonextfrom
pcie_sriov_qemu
Feb 3, 2026
Merged

Fix QEMU CVEs#713
andy-vm merged 1 commit intonextfrom
pcie_sriov_qemu

Conversation

@rshanm8x
Copy link
Contributor

Add patch for CVE-2025-54566 CVE-2025-54567

Merge Checklist

All boxes should be checked before merging the PR

  • The changes in the PR have been built and tested
  • [] cgmanifest file has been updated if required
  • Ready to merge

Description

[Black Duck] Security vulnerabilities (GHSA-399m-rf4f-w5x4, GHSA-c2q6-w8rj-wvhw) were detected in qemu-9.1.0-5.emt3.
QEMU has been upgraded to resolve the reported issues.

Any Newly Introduced Dependencies

How Has This Been Tested?

Created rpm and uploaded to BDBA scan along with BDBA config and found no CVEs.
image

Add patch for CVE-2025-54566 CVE-2025-54567

Signed-off-by: RajeshX Shanmugam <rajesh1x.shanmugam@intel.com>
@rshanm8x rshanm8x requested a review from a team as a code owner January 30, 2026 14:31
@rshanm8x rshanm8x self-assigned this Jan 30, 2026
@rshanm8x rshanm8x requested a review from cheeyanglee January 30, 2026 14:32
Copy link
Contributor

@liulis-sg liulis-sg left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Patch is picked up from intel/Intel-distribution-of-QEMU@8e06d09;

LGTM

Copy link
Contributor

@andy-vm andy-vm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@andy-vm andy-vm merged commit 14aad83 into next Feb 3, 2026
2 checks passed
@andy-vm andy-vm deleted the pcie_sriov_qemu branch February 3, 2026 01:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants