Package: qemu CVE IDs: CVE-2017-9310, CVE-2017-9330, CVE-2017-9373, CVE-2017-9374, CVE-2017-9375, CVE-2017-9524, CVE-2017-10664, CVE-2017-10911 Vulnerabilities: - CVE-2017-9310: Denial of service via infinite loop in e1000e NIC emulation. - CVE-2017-9330: Denial of service via infinite loop in USB OHCI emulation. - CVE-2017-9373: Denial of service via memory leak in IDE AHCI emulation. - CVE-2017-9374: Denial of service via memory leak in USB EHCI emulation. - CVE-2017-9375: Denial of service via memory leak in USB XHCI emulation. - CVE-2017-9524: Denial of service in qemu-nbd server. - CVE-2017-10664: Denial of service in qemu-nbd server. - CVE-2017-10911: Information leak in Xen blkif response handling. Recommendation: Upgrade your qemu packages. Fixes in versions: - Stable distribution (stretch): 1:2.8+dfsg-6+deb9u1 - Unstable distribution (sid): Fixes will be applied soon This advisory pertains to Debian and its distributions.