QEMU: Multiple vulnerabilities Multiple vulnerabilities have been found in QEMU, the worst of which could lead to the execution of arbitrary code on the host system. qemu 2017-02-21 2017-02-21 606264 606720 606722 607000 607100 607766 608034 608036 608038 608520 608728 local 2.8.0-r1 2.8.0-r1

QEMU is a generic and open source machine emulator and virtualizer.

Multiple vulnerabilities have been discovered in QEMU. Please review the CVE identifiers referenced below for details.

A local attacker could potentially execute arbitrary code with privileges of QEMU process on the host, gain privileges on the host system, cause a Denial of Service condition, or obtain sensitive information.

There is no known workaround at this time.

All QEMU users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/qemu-2.8.0-r1"
CVE-2016-10155 CVE-2017-2615 CVE-2017-5525 CVE-2017-5552 CVE-2017-5578 CVE-2017-5579 CVE-2017-5667 CVE-2017-5856 CVE-2017-5857 CVE-2017-5898 CVE-2017-5931 whissi whissi