All of lore.kernel.org
 help / color / mirror / Atom feed
* CVEs and the QEMU 11.1 release
@ 2026-07-27 13:52 Stefan Hajnoczi
  2026-07-27 14:28 ` Daniel P. Berrangé
  2026-07-27 16:18 ` Christian Borntraeger
  0 siblings, 2 replies; 3+ messages in thread
From: Stefan Hajnoczi @ 2026-07-27 13:52 UTC (permalink / raw)
  To: qemu-devel; +Cc: Peter Maydell, Richard Henderson

Hi,
QEMU v11.1.0-rc2 will be tagged tomorrow and -rc3 a week after that.
The project currently has a backlog of confidential and potentially
CVE-worthy bugs. Maintainers are triaging these bug reports and fixes
are being sent to the mailing list.

Holding up the QEMU 11.1 release for any and all CVE fixes is not
realistic this time around since there are still a number of upcoming
fixes expected over the coming weeks. Many CVEs are low severity and
do not pose enough of a security risk to hold up the 11.1 release.

I'd like to approach CVEs as follows:
1. CVE fix authors and maintainers should indicate the severity in
cover letters. This will ensure that serious CVE fixes are included in
v11.1.0 while less serious CVEs do not hold up the release.
2. Low severity CVE fixes should go into the -stable branch if they
cannot make it into v11.1.0.

I will be looking at CVE fixes on a case-by-case when -rc3 is tagged.
If you feel a fix is critical, please let me know.

Stefan


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-07-27 16:19 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 13:52 CVEs and the QEMU 11.1 release Stefan Hajnoczi
2026-07-27 14:28 ` Daniel P. Berrangé
2026-07-27 16:18 ` Christian Borntraeger

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.