Skip to content

Commit ab3490a

Browse files
jslobodzianazurelinux-securityRedent0r
authored
Revert: Patch qemu for CVE-2025-14876, CVE-2024-8354 [MEDIUM] (#16173) (#16399)
Signed-off-by: Saul Paredes <saulparedes@microsoft.com> Co-authored-by: Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> Co-authored-by: Saul Paredes <30801614+Redent0r@users.noreply.github.com>
1 parent 9f3c740 commit ab3490a

File tree

8 files changed

+422
-156
lines changed

8 files changed

+422
-156
lines changed

SPECS/qemu/CVE-2024-8354.patch

Lines changed: 0 additions & 74 deletions
This file was deleted.

SPECS/qemu/CVE-2025-14876.patch

Lines changed: 0 additions & 50 deletions
This file was deleted.

SPECS/qemu/qemu.spec

Lines changed: 1 addition & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -435,7 +435,7 @@ Obsoletes: sgabios-bin <= 1:0.20180715git-10.fc38
435435
Summary: QEMU is a FAST! processor emulator
436436
Name: qemu
437437
Version: 9.1.0
438-
Release: 3%{?dist}
438+
Release: 1%{?dist}
439439
License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND FSFAP AND GPL-1.0-or-later AND GPL-2.0-only AND GPL-2.0-or-later AND GPL-2.0-or-later WITH GCC-exception-2.0 AND LGPL-2.0-only AND LGPL-2.0-or-later AND LGPL-2.1-only AND LGPL-2.1-or-later AND MIT AND LicenseRef-Fedora-Public-Domain AND CC-BY-3.0
440440
URL: http://www.qemu.org/
441441

@@ -448,8 +448,6 @@ Patch2: 0002-Disable-failing-tests-on-azl.patch
448448
Patch3: CVE-2021-20255.patch
449449
Patch4: CVE-2025-11234.patch
450450
Patch5: CVE-2025-12464.patch
451-
Patch6: CVE-2024-8354.patch
452-
Patch7: CVE-2025-14876.patch
453451

454452
Source10: qemu-guest-agent.service
455453
Source11: 99-qemu-guest-agent.rules
@@ -3409,12 +3407,6 @@ useradd -r -u 107 -g qemu -G kvm -d / -s /sbin/nologin \
34093407

34103408

34113409
%changelog
3412-
* Wed Mar 25 2026 Aditya Singh <v-aditysing@microsoft.com> - 9.1.0-3
3413-
- Bump to rebuild with updated glibc
3414-
3415-
* Wed Mar 11 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 9.1.0-2
3416-
- Patch for CVE-2025-14876, CVE-2024-8354
3417-
34183410
* Fri Feb 06 2026 Aadhar Agarwal <aadagarwal@microsoft.com> - 9.1.0-1
34193411
- Upgrade to QEMU 9.1.0
34203412
- Remove CVE patches merged upstream: CVE-2023-6683, CVE-2023-6693,

0 commit comments

Comments
 (0)