Re: [Qemu-devel] [PATCH v2 00/28] Series short description

2017-02-27 Thread Stefan Hajnoczi
On Sun, Feb 26, 2017 at 11:41:32PM +0100, Greg Kurz wrote: > This series tries to fix CVE-2016-9602 reported by Jann Horn of Google > Project Zero: > > https://bugzilla.redhat.com/show_bug.cgi?id=1413929 > > This vulnerability affects all accesses to the underlying filesystem in > the "local" bac

Re: [Qemu-devel] [PATCH v2 00/28] Series short description

2017-02-27 Thread Stefan Hajnoczi
On Sun, Feb 26, 2017 at 11:41:32PM +0100, Greg Kurz wrote: > This series tries to fix CVE-2016-9602 reported by Jann Horn of Google > Project Zero: > > https://bugzilla.redhat.com/show_bug.cgi?id=1413929 > > This vulnerability affects all accesses to the underlying filesystem in > the "local" bac

[Qemu-devel] [PATCH v2 00/28] Series short description

2017-02-26 Thread Greg Kurz
This series tries to fix CVE-2016-9602 reported by Jann Horn of Google Project Zero: https://bugzilla.redhat.com/show_bug.cgi?id=1413929 This vulnerability affects all accesses to the underlying filesystem in the "local" backend code. If QEMU is started with: -fsdev local,security_model=,path=/