From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: QEMU update (security) Date: Sun, 4 Sep 2016 16:20:44 -0400 Message-ID: <20160904202044.GA32311@jasmine> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="rS8CxjVDS/+yyDmU" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:56359) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bgdui-0008NY-55 for guix-devel@gnu.org; Sun, 04 Sep 2016 16:21:13 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bgdud-0007Hb-Op for guix-devel@gnu.org; Sun, 04 Sep 2016 16:21:10 -0400 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:37073) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bgdub-0007F7-Dk for guix-devel@gnu.org; Sun, 04 Sep 2016 16:21:07 -0400 Received: from localhost (m825736d0.tmodns.net [208.54.87.130]) by mail.messagingengine.com (Postfix) with ESMTPA id 2DC2FCCDCC for ; Sun, 4 Sep 2016 16:20:55 -0400 (EDT) Content-Disposition: inline List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org --rS8CxjVDS/+yyDmU Content-Type: multipart/mixed; boundary="1yeeQ81UyVL57Vl7" Content-Disposition: inline --1yeeQ81UyVL57Vl7 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline This updates QEMU to the latest release, 2.7.0. It fixes at least one security bug (I think that every new QEMU release fixes security bugs): http://seclists.org/oss-sec/2016/q3/394 Tested on x86-64. --1yeeQ81UyVL57Vl7 Content-Type: text/plain; charset=us-ascii Content-Disposition: attachment; filename="0001-gnu-qemu-Update-to-2.7.0-fixes-CVE-2016-7116.patch" Content-Transfer-Encoding: quoted-printable =46rom a46d80d697e2ed93596a69b9f170b645f8b608a0 Mon Sep 17 00:00:00 2001 =46rom: Leo Famulari Date: Sun, 4 Sep 2016 02:53:37 -0400 Subject: [PATCH] gnu: qemu: Update to 2.7.0 [fixes CVE-2016-7116]. * gnu/packages/qemu.scm (qemu): Update to 2.7.0. [arguments]: Adjust path in 'disable-test-qga' phase. --- gnu/packages/qemu.scm | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/gnu/packages/qemu.scm b/gnu/packages/qemu.scm index 1b9f0ad..aee6a75 100644 --- a/gnu/packages/qemu.scm +++ b/gnu/packages/qemu.scm @@ -69,14 +69,14 @@ (define-public qemu (package (name "qemu") - (version "2.6.1") + (version "2.7.0") (source (origin (method url-fetch) (uri (string-append "http://wiki.qemu-project.org/download/qe= mu-" version ".tar.bz2")) (sha256 (base32 - "1l88iqk0swqccrnjwczgl9arqsvy77bis862zxajy7z3dqdzshj9")))) + "0lqyz01z90nvxpc3nx4djbci7hx62cwvs5zwd6phssds0sap6vij")))) (build-system gnu-build-system) (arguments '(;; Running tests in parallel can occasionally lead to failures, lik= e: @@ -125,7 +125,7 @@ (setenv "V" "1"))) (add-before 'check 'disable-test-qga (lambda _ - (substitute* "tests/Makefile" + (substitute* "tests/Makefile.include" ;; Comment out the test-qga test, which needs /sys and ;; fails within the build environment. (("check-unit-.* tests/test-qga" all) --=20 2.10.0 --1yeeQ81UyVL57Vl7-- --rS8CxjVDS/+yyDmU Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJXzIIYAAoJECZG+jC6yn8IduUP/iMf5N4IG8ixoSpgi0gHxh05 a5lHm92yjcbUTjwpL6RbipO6KSr3UEWD1ObXHV1sPz5lbsWpbNJBJ8R9tSHtdkqR XAVDQjK1F5mDSqRGRqdZxUDBTLDefLs3bv5rJV7XkuGT+z/uj+RNPKuz5QWjXUeY 6M4JZhIOuLxO/H/YDgOcXxThOCdRbttigV87SikL4WRrmRSLBfF1BxBITredC7/g ymCxeiQTd32lQiCwtZPUDMrtDe8BMS930kAx9/Gtf3xqy1C34TK9gv9/vV8ns0cS qDjbqYHhDydwG/z7RNWvbdjSOw1kg3F6ISn3mkFfpw5oi+EInhWD4CJjs6N8WHlL uI6dnLpGJSY8c6AOuJ9ISgz9BlAtxUAU5Vk5YBhNKSnvUW6d+nXyoAonmfCgZ3pZ 96Lx0jffIsXXZtu8HZD7V+8vBoe5J0Fx4G+rkEjQ9Sh/1QjPS3x4Syct6+EKp6Pk WpR2uZ/dHPLSwAUoI7yqrpjegraonGcB0xieY+AhRZzFedqK5k4NsZqYIPHHYG1E O/K5F4ICsYPirQvDw4MRoU69+88McdYCftOdoIgeWCqskvDOVgm2R4UxAZtnUfB7 6freQOAca67iUD4BBVnf0hF38eDkafXtbXpj5wEMlkUmpnBaQ/ixC6BWXbI+YkVI 3kgyqx7PlPRuq8zWEZ7A =emfr -----END PGP SIGNATURE----- --rS8CxjVDS/+yyDmU--