Vulnerability Bulletins

DSA-3088 qemu-kvm - security update

   
Affected software Debian
 
Paolo Bonzini of Red Hat discovered that the blit region checks wereinsufficient in the Cirrus VGA emulator in qemu-kvm, a fullvirtualization solution on x86 hardware. A privileged guest user coulduse this flaw to write into qemu address space on the host, potentiallyescalating their privileges to those of the qemu host process.

More info:

https://www.debian.org/security/2014/dsa-3088