qemu (1:2.8+dfsg-6+deb9u2) stretch-security; urgency=high
* actually apply the nbd server patches, not only include in debian/patches/
Really closes: #865755, CVE-2017-9524
* slirp-check-len-against-dhcp-options-array-end-CVE-2017-11434.patch
Closes: #869171, CVE-2017-11434
* exec-use-qemu_ram_ptr_length-to-access-guest-ram-CVE-2017-11334.patch
Closes: #869173, CVE-2017-11334
* usb-redir-fix-stack-overflow-in-usbredir_log_data-CVE-2017-10806.patch
Closes: #867751, CVE-2017-10806
* add reference to #869706 to
* disable xhci recursive calls fix for now, as it causes instant crash
Reopens: #864219, CVE-2017-9375
Closes: #869945
-- Michael Tokarev <> Wed, 02 Aug 2017 16:57:34 +0300
qemu (1:2.8+dfsg-6+deb9u1) stretch-security; urgency=high
* net-e1000e-fix-an-infinite-loop-issue-CVE-2017-9310.patch
