-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 14 Aug 2025 13:49:37 +0300 Source: qemu Architecture: source Version: 1:10.1.0~rc3+ds-2 Distribution: experimental Urgency: medium Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org> Changed-By: Michael Tokarev <mjt@tls.msk.ru> Changes: qemu (1:10.1.0~rc3+ds-2) experimental; urgency=medium . * d/binfmt-install: stop using C (Credentials) flag for binfmt_misc registration. This means suid and sgid binaries under qemu-user will work without changing credentials. This is a serious security issue, since qemu-user never supposed to be used in this way, and it is trivial to get elevated privileges for an attacker if there's any suid/sgid binary under qemu-user which is runnable for an attacker. This change might break CI/testing environment expectations. * remove qemu-user-static package (& qemu-debootstrap), it is now provided by qemu-user-binfmt package * d/control: remove long-forgotten qemu-system-common dependency on acl (for #762192) which is not needed Checksums-Sha1: a326404a9c256cfd36ecb78e254955edcfb6a810 12253 qemu_10.1.0~rc3+ds-2.dsc bfc6de97dde8c5aabe1d26127ed31b5ab1c7330c 121512 qemu_10.1.0~rc3+ds-2.debian.tar.xz e644f6d1096fc996f1e4f59d0f5d1116bc61aa58 7549 qemu_10.1.0~rc3+ds-2_source.buildinfo Checksums-Sha256: fdbd9565238109fa868cf4c9af5c6b48f4fdb830758f8d94da94f591a030f138 12253 qemu_10.1.0~rc3+ds-2.dsc 2bd414318d55b7b909fca525b4302b3324a0b89b6adea05d0b77ad31c0697822 121512 qemu_10.1.0~rc3+ds-2.debian.tar.xz f29691e335b9c37e1bc32cff7fb9ffec29f37688d1f9716329275976679305cc 7549 qemu_10.1.0~rc3+ds-2_source.buildinfo Files: 46908e9e6a128de355601aecd45a7ef7 12253 otherosfs optional qemu_10.1.0~rc3+ds-2.dsc 16e795ccb2371d3f4e3f1252fda6d2e3 121512 otherosfs optional qemu_10.1.0~rc3+ds-2.debian.tar.xz 61dea915c224a55469fa8149d35983bf 7549 otherosfs optional qemu_10.1.0~rc3+ds-2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmidv4cACgkQgqpKJDse lHjVyA/+MpY4KOvelhmc+4QXxhfm9Vdpgm029MgRmkL1gId/CY/c/4IVXQ6AXjPr VuBPMvyi9wUI1YmUCKfUWPBTRnAt83gIZVX6DvjT0624xx16v+seEJMkvpzOyqRR YjFf97ddR+m9oTFYTSaJJbSNFDX7ZszmMsxHIWVhOWTcIaBW7Zx9DkcoG3zcN/Fw lMunYomVe20X/zvp8ykCMXCqHBHnzEluX5xbhJi925xO3vLbxc7Nfx9eO4GZWhel SsDbHv3W8w6037vGgCwTHgeerKjvX3jyLb+N/TglNCeqoxuvpF0Pi9G17157PzfH aR9ewB6506+wkUCQUDXtPkQu4yEx+QDiqQ3PvoW5MLECltIlQontLuO/8RV707Ic zVwC/XV6wCD2WbgCZ+MZN0HuSN9GcFWXmJXS9hVY07irjXDq10dUFhIFdQXryhe4 AbEjkyBIzNo9GW96kjvi1X7KzMy0LAWMSS+Rkw724B2RIdp5jwqSxA+XgoOfniQM 3YkJz+92iIgYK8ERSTno/mEv6a9FLF6lQ7ShNvIpMLd0n9tDg1WaTjFy+jILWLeQ kYKqV0K9ZsqJ1f75c541CPKDMTA/NmV3VM3dRH2MHxEnRFFr56cDl9eU2a3DXED4 2wHSHGYTluiU1yjUfsYWNQJaq/K1NFi+0+0EnZRqOqIBNj7Y/cU= =eDP4 -----END PGP SIGNATURE-----
Attachment:
pgp_ueHWoPi0I.pgp
Description: PGP signature