All of lore.kernel.org
 help / color / mirror / Atom feed
* CVEs and the QEMU 11.1 release
@ 2026-07-27 13:52 Stefan Hajnoczi
  2026-07-27 14:28 ` Daniel P. Berrangé
  2026-07-27 16:18 ` Christian Borntraeger
  0 siblings, 2 replies; 3+ messages in thread
From: Stefan Hajnoczi @ 2026-07-27 13:52 UTC (permalink / raw)
  To: qemu-devel; +Cc: Peter Maydell, Richard Henderson

Hi,
QEMU v11.1.0-rc2 will be tagged tomorrow and -rc3 a week after that.
The project currently has a backlog of confidential and potentially
CVE-worthy bugs. Maintainers are triaging these bug reports and fixes
are being sent to the mailing list.

Holding up the QEMU 11.1 release for any and all CVE fixes is not
realistic this time around since there are still a number of upcoming
fixes expected over the coming weeks. Many CVEs are low severity and
do not pose enough of a security risk to hold up the 11.1 release.

I'd like to approach CVEs as follows:
1. CVE fix authors and maintainers should indicate the severity in
cover letters. This will ensure that serious CVE fixes are included in
v11.1.0 while less serious CVEs do not hold up the release.
2. Low severity CVE fixes should go into the -stable branch if they
cannot make it into v11.1.0.

I will be looking at CVE fixes on a case-by-case when -rc3 is tagged.
If you feel a fix is critical, please let me know.

Stefan


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: CVEs and the QEMU 11.1 release
  2026-07-27 13:52 CVEs and the QEMU 11.1 release Stefan Hajnoczi
@ 2026-07-27 14:28 ` Daniel P. Berrangé
  2026-07-27 16:18 ` Christian Borntraeger
  1 sibling, 0 replies; 3+ messages in thread
From: Daniel P. Berrangé @ 2026-07-27 14:28 UTC (permalink / raw)
  To: Stefan Hajnoczi; +Cc: qemu-devel, Peter Maydell, Richard Henderson

On Mon, Jul 27, 2026 at 09:52:21AM -0400, Stefan Hajnoczi wrote:
> Hi,
> QEMU v11.1.0-rc2 will be tagged tomorrow and -rc3 a week after that.
> The project currently has a backlog of confidential and potentially
> CVE-worthy bugs. Maintainers are triaging these bug reports and fixes
> are being sent to the mailing list.
> 
> Holding up the QEMU 11.1 release for any and all CVE fixes is not
> realistic this time around since there are still a number of upcoming
> fixes expected over the coming weeks. Many CVEs are low severity and
> do not pose enough of a security risk to hold up the 11.1 release.
> 
> I'd like to approach CVEs as follows:
> 1. CVE fix authors and maintainers should indicate the severity in
> cover letters. This will ensure that serious CVE fixes are included in
> v11.1.0 while less serious CVEs do not hold up the release.
> 2. Low severity CVE fixes should go into the -stable branch if they
> cannot make it into v11.1.0.
> 
> I will be looking at CVE fixes on a case-by-case when -rc3 is tagged.
> If you feel a fix is critical, please let me know.

IMHO, we shouldn't do anything special wrt CVEs for the release.
Just follow our normal bug evaluation criteria which get increasingly
strict in later RC's, such that rc3 is largely just regression fixes.

No matter how many CVE fixes we might try to rush into 11.1, all
indications are that we're going to have countless more arrive
on an ongoing basis for a good while yet and just have to accept
that. 

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: CVEs and the QEMU 11.1 release
  2026-07-27 13:52 CVEs and the QEMU 11.1 release Stefan Hajnoczi
  2026-07-27 14:28 ` Daniel P. Berrangé
@ 2026-07-27 16:18 ` Christian Borntraeger
  1 sibling, 0 replies; 3+ messages in thread
From: Christian Borntraeger @ 2026-07-27 16:18 UTC (permalink / raw)
  To: Stefan Hajnoczi, qemu-devel
  Cc: Peter Maydell, Richard Henderson, Michael Tokarev

Am 27.07.26 um 15:52 schrieb Stefan Hajnoczi:
> Hi,
> QEMU v11.1.0-rc2 will be tagged tomorrow and -rc3 a week after that.
> The project currently has a backlog of confidential and potentially
> CVE-worthy bugs. Maintainers are triaging these bug reports and fixes
> are being sent to the mailing list.
> 
> Holding up the QEMU 11.1 release for any and all CVE fixes is not
> realistic this time around since there are still a number of upcoming
> fixes expected over the coming weeks. Many CVEs are low severity and
> do not pose enough of a security risk to hold up the 11.1 release.
> 
> I'd like to approach CVEs as follows:
> 1. CVE fix authors and maintainers should indicate the severity in
> cover letters. This will ensure that serious CVE fixes are included in
> v11.1.0 while less serious CVEs do not hold up the release.
> 2. Low severity CVE fixes should go into the -stable branch if they
> cannot make it into v11.1.0.
> 
> I will be looking at CVE fixes on a case-by-case when -rc3 is tagged.
> If you feel a fix is critical, please let me know.
I agree with not holding off. People will continue to run LLMs to find
new bugs and it will take one or two releases to get back to normal.
We should rather have our fixes process working. I fear that Michael
Tokarev will have plenty of work.


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-07-27 16:19 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 13:52 CVEs and the QEMU 11.1 release Stefan Hajnoczi
2026-07-27 14:28 ` Daniel P. Berrangé
2026-07-27 16:18 ` Christian Borntraeger

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.