carlwgeorge / rpms / qemu

Forked from rpms/qemu a year ago
Clone

eaa6ce4 CVE-2016-7907: net: imx: infinite loop (bz #1381182)

Authored and Committed by crobinso 7 years ago
26 files changed. 1566 lines added. 1 lines removed.
0043-net-imx-limit-buffer-descriptor-count.patch
file added
+61
0044-audio-ac97-add-exit-function.patch
file added
+49
0045-audio-es1370-add-exit-function.patch
file added
+52
0046-watchdog-6300esb-add-exit-function.patch
file added
+43
0047-virtio-gpu-3d-fix-memory-leak-in-resource-attach-bac.patch
file added
+38
0048-virtio-gpu-fix-memory-leak-in-resource-attach-backin.patch
file added
+32
0049-sd-sdhci-check-data-length-during-dma_memory_read.patch
file added
+34
0050-megasas-fix-guest-triggered-memory-leak.patch
file added
+61
0051-virtio-gpu-fix-resource-leak-in-virgl_cmd_resource_u.patch
file added
+45
0052-usb-ccid-check-ccid-apdu-length.patch
file added
+32
0053-sd-sdhci-check-transfer-mode-register-in-multi-block.patch
file added
+51
0054-eth-Extend-vlan-stripping-functions.patch
file added
+125
0055-NetRxPkt-Fix-memory-corruption-on-VLAN-header-stripp.patch
file added
+117
0056-NetRxPkt-Do-not-try-to-pull-more-data-than-present.patch
file added
+30
0057-NetRxPkt-Account-buffer-with-ETH-header-in-IOV-lengt.patch
file added
+34
0058-usb-ohci-limit-the-number-of-link-eds.patch
file added
+49
0059-display-cirrus-ignore-source-pitch-value-as-needed-i.patch
file added
+69
0060-cirrus-handle-negative-pitch-in-cirrus_invalidate_re.patch
file added
+47
0061-cirrus-allow-zero-source-pitch-in-pattern-fill-rops.patch
file added
+99
0062-cirrus-fix-blit-address-mask-handling.patch
file added
+101
0063-cirrus-fix-oob-access-issue-CVE-2017-2615.patch
file added
+45
0064-cirrus-fix-patterncopy-checks.patch
file added
+101
0065-Revert-cirrus-allow-zero-source-pitch-in-pattern-fil.patch
file added
+100
0066-cirrus-add-blit_is_unsafe-call-to-cirrus_bitblt_cput.patch
file added
+46
0067-egl-helpers-Support-newer-MESA-versions.patch
file added
+33
qemu.spec
file modified
+72 -1
    CVE-2016-7907: net: imx: infinite loop (bz #1381182)
    CVE-2017-5525: audio: memory leakage in ac97 (bz #1414110)
    CVE-2017-5526: audio: memory leakage in es1370 (bz #1414210)
    CVE-2016-10155 watchdog: memory leakage in i6300esb (bz #1415200)
    CVE-2017-5552: virtio-gpu-3d: memory leakage (bz #1415283)
    CVE-2017-5578: virtio-gpu: memory leakage (bz #1415797)
    CVE-2017-5667: sd: sdhci OOB access during multi block transfer (bz #1417560)
    CVE-2017-5856: scsi: megasas: memory leakage (bz #1418344)
    CVE-2017-5857: virtio-gpu-3d: host memory leakage in virgl_cmd_resource_unref (bz #1418383)
    CVE-2017-5898: usb: integer overflow in emulated_apdu_from_guest (bz #1419700)
    CVE-2017-5987: sd: infinite loop issue in multi block transfers (bz #1422001)
    CVE-2017-6058: vmxnet3: OOB access when doing vlan stripping (bz #1423359)
    CVE-2017-6505: usb: an infinite loop issue in ohci_service_ed_list (bz #1429434)
    CVE-2017-2615: cirrus: oob access while doing bitblt copy backward (bz #1418206)
    CVE-2017-2620: cirrus: potential arbitrary code execution (bz #1425419)
    Fix spice GL with new mesa/libglvnd (bz #1431905)
    
        
file modified
+72 -1