2009
kvm (72+dfsg-5~lenny3) stable-security; urgency=high
* Non-maintainer upload by the Security Team. * Considers hypercalls valid only if issued from guest ring 0 (CVE-2009-3290) (Closes: 548975) * Add patch from upstream qemu for CVE-2008-5714 (Closes: #509997)
-- Giuseppe Iuculano <iuculano@debian.org> Sun, 11 Oct 2009 11:16:45 +0200
kvm (72+dfsg-5~lenny2) stable-security; urgency=high
* Non-maintainer upload by the security team * x86: check for cr3 validity in ioctl_set_sregs (CVE-2009-2287)
-- dann frazier <dannf@debian.org> Sun, 05 Jul 2009 23:15:38 -0600
kvm (72+dfsg-5~lenny1) stable-proposed-updates; urgency=low
* Rebuild 72+dfsg-5 for lenny
* debian/patches/restore_option_roms.patch: fix hang on reboot with virtio,
thanks to Jeroen Dekkers for finding the cause. (closes: #506972)
-- Jan Lübbe <jluebbe@debian.org> Fri, 20 Mar 2009 10:01:08 +0100
2008
kvm (72+dfsg-4) unstable; urgency=high
* debian/patches/core-2008-1210.patch: fix remote DoS via VNC
(CORE-2008-1210/CVE-2008-2382).
-- Jan Lübbe <jluebbe@debian.org> Wed, 24 Dec 2008 12:23:06 +0100
kvm (72+dfsg-3) unstable; urgency=medium
* Apply patch from qemu (62_fix-ptyblocking.patch) which fixes a lockup
when using a pty as serial console, which caused problems for libvirt
users. Thanks to Peter Palfrader and Riku Voipio (closes: #494831)
-- Jan Lübbe <jluebbe@debian.org> Thu, 20 Nov 2008 16:41:26 +0100
kvm (72+dfsg-2) unstable; urgency=medium
* Merge changes from NMU, thanks to Thomas Viehmann
* Use a sane method for creating the kvm group, thanks to Josh Tripplet
(closes: #502299)
-- Jan Lübbe <jluebbe@debian.org> Thu, 16 Oct 2008 18:22:41 +0200
kvm (72+dfsg-1.1) unstable; urgency=low
* Non-maintainer upload.
* Change path of diverted kvm modules when kernel >= 2.6.26.
(Closes: #494873).
-- Thomas Viehmann <tv@beamnet.de> Fri, 12 Sep 2008 11:48:31 +0200
kvm (72+dfsg-1) unstable; urgency=low
* New upstream release (closes: #493536) * Cherry-pick a commit from qemu which fixes migration * Cherry-pick a commit from kvm which fixes the external module with 2.6.26 * Reenable audio drivers and cards (closes: #491676)
-- Jan Lübbe <jluebbe@debian.org> Mon, 11 Aug 2008 19:51:51 +0200
kvm (71+dfsg-1) unstable; urgency=low
* New upstream release
-- Jan Lübbe <jluebbe@debian.org> Sat, 19 Jul 2008 15:52:45 +0200
kvm (70+dfsg-1) unstable; urgency=low
* New upstream release
* Merge changes from Ubuntu in debian/control
- Only Build-Depend on device-tree-compiler on PowerPC
- Change linux-{image,headers,source}-2.6 to just
linux-{image,headers,source}
- Don't suggest sudo
* Reenable CPU emulation
* Update to policy 3.8.0.0
- Add debian/README.source
-- Jan Lübbe <jluebbe@debian.org> Tue, 17 Jun 2008 18:55:51 +0200
kvm (69+dfsg-1) unstable; urgency=low
[ Jan Lübbe ] * New upstream releases (closes: #481989) - Fixes CVE-2007-1320 (Cirrus LGD-54XX "bitblt" heap overflow) - Fixes CVE-2008-2004 (format guessing vulnerability, drop the patch) - Update debian patches * Update upstream changelog * Update Vcs-* headers to git.debian.org * Drop kvm-data again, build and ship only those files relevant to the target arch [ Soren Hansen ] * 03_bios_no_ssp.patch: - Pass -fno-stack-protector to gcc when building the bios image. * qemu_vnc_ext_key_event.diff: - Implement the Extended KeyEvent extension in kvm's embedded VNC server. * Add kvm init script that loads the appropriate kernel modules. * Update package description - We no longer support cpu emulation, so hardware support is required. - The standard kernel images provide the kernel modules, so compiling them yourself from kvm-source is now optional. - qemu is no longer needed for creating disk images, since we have kvm-img now. * Move kvm-source from "Recommends:" of kvm to "Suggests:", since the modules are in the standard kernel images. * Update CVE-2008-0928.patch to allow any bdrv request if vm is not running. This fixes the savevm monitor command. - This also fixes booting with qcow2 images (closes: #470664)
-- Jan Lübbe <jluebbe@debian.org> Mon, 26 May 2008 16:55:21 +0200
kvm (66+dfsg-1.1) unstable; urgency=high
* Non-maintainer upload by the security team
* Merge the fixes for the security issues in the embedded qemu
version (Closes: #480011) Thanks to Jamie Strandboge
- Add CVE-2007-1320+1321+1322+1366+2893.patch from from qemu 0.9.1-1
to address the following issues:
- Note: CVE-2007-2893 is the same as CVE-2007-1323 referenced in DSA-1284-1.
- Note: CVE-2007-5729 and CVE-2007-5730 are the same as CVE-2007-1321
referenced in DSA-1284-1.
- Cirrus LGD-54XX "bitblt" heap overflow.
- NE2000 "mtu" heap overflow.
- QEMU "net socket" heap overflow.
- QEMU NE2000 "receive" integer signedness error.
- Infinite loop in the emulated SB16 device.
- Unprivileged "aam" instruction does not correctly handle the
undocumented divisor operand.
- Unprivileged "icebp" instruction will halt emulation.
* Include patch which defaults to existing behaviour (probing based on file
contents), so it still requires the mgmt app (e.g. libvirt xml) to
pass a new "format=raw" parameter for raw disk images
- Fixes possible privilege escalation, which could allow guest users
to read arbitrary files on the host by modifying the header to identify
a different format (Closes: #481204) Fixes: CVE-2008-2004
-- Steffen Joeris <white@debian.org> Tue, 20 May 2008 13:28:14 +0000
kvm (66+dfsg-1) unstable; urgency=low
* New upstream release
* Update upstream changelog
* Ship the userspace utilities
- Depend on python for the scripts
-- Jan Lübbe <jluebbe@debian.org> Thu, 17 Apr 2008 22:23:14 +0200
kvm (65+dfsg-2) unstable; urgency=low
* Install PXE boot ROMs only if they exists and Build-Depend on
etherboot only on i386
- This allows building on amd64 (closes: #469125)
* Disable qemu CPU emulation and drop Build-Depend on gcc-3.4
(closes: #440430)
* Don't Recommend qemu (we ship qemu-img as kvm-img)
* Move vde2 from Recommends to Suggests
* Suggest samba for the -smb option (closes: #474209)
-- Jan Lübbe <jluebbe@debian.org> Thu, 10 Apr 2008 22:52:26 +0200
kvm (65+dfsg-1) unstable; urgency=low
* New upstream release
* Update upstream changelog
* Put the link to ../packages/default.sh into /usr/share/modass/overrides/
as suggested by m-a's HOWTO-DEVEL
- This also avoides a Conflicts/Replaces against older kvm packages
(closes: #473910)
-- Jan Lübbe <jluebbe@debian.org> Tue, 08 Apr 2008 18:49:34 +0200
kvm (64+dfsg-1) unstable; urgency=low
* New upstream release * Update upstream changelog * Build-Depend on device-tree-compiler and build bamboo.dtb from source * Clean up debian/rules * Drop patch included upstream (02_snapshot_use_tmpdir.patch)
-- Jan Lübbe <jluebbe@debian.org> Tue, 01 Apr 2008 17:21:14 +0200
kvm (63+dfsg-2) unstable; urgency=low
* Depend on libncurses5-dev to allow the curses interface in addition
to SDL (closes: #471292)
* Use 02_snapshot_use_tmpdir from debian qemu svn r298 (closes: #470757)
* Correct my name in debian/control
-- Jan Lübbe <jluebbe@debian.org> Wed, 26 Mar 2008 22:18:43 +0100
kvm (63+dfsg-1) unstable; urgency=low
* New upstream release * Update upstream changelog (from mailing list) * Fix CVE-2008-0928 using the patch in the bugreport (closes: #469666)
-- Jan Lübbe <jluebbe@debian.org> Tue, 11 Mar 2008 10:48:29 +0100
kvm (62+dfsg-3) unstable; urgency=low
* Build a kvm-data package for the files loaded into the VM
(closes: #469125)
-- Jan Luebbe <jluebbe@debian.org> Fri, 07 Mar 2008 00:15:56 +0100
kvm (62+dfsg-2) unstable; urgency=low
* Use PXE boot ROMs from the Etherboot package
-- Jan Luebbe <jluebbe@debian.org> Sat, 01 Mar 2008 17:33:00 +0100
kvm (62+dfsg-1) unstable; urgency=low
* New upstream release
- even more resolutions for -std-vga (closes: #463629)
* Update upstream changelog
-- Jan Luebbe <jluebbe@debian.org> Fri, 29 Feb 2008 21:51:02 +0100
kvm (61+dfsg-1) unstable; urgency=low
* The "Live from FOSDEM" release * New upstream release * Update upstream changelog * Drop dependency on vgabios * Switch to git for packaging, update Vcs-* in debian/control
-- Jan Luebbe <jluebbe@debian.org> Sat, 23 Feb 2008 17:22:29 +0100
kvm (60+dfsg-1) unstable; urgency=low
* New upstream release * Update upstream changelog * Drop restore-IO_MEM_ROM-mark.patch (included upstream) * Build and use the vgabios shipped with kvm (closes: #462434) * Use install_linux_boot.patch from Ubuntu to fix the -kernel option (closes: #412022)
-- Jan Luebbe <jluebbe@debian.org> Fri, 25 Jan 2008 16:12:41 +0100
kvm (58+dfsg-2) unstable; urgency=low
* Use patch from kvm-devel list to fix booting with some linux kernels
(closes: #458481)
-- Jan Luebbe <jluebbe@debian.org> Mon, 21 Jan 2008 11:20:17 +0100
2007
kvm (58+dfsg-1) unstable; urgency=low
* The "Live from 24c3 in Berlin" release * New upstream release (closes: #452392) * Update upstream changelog * Update to policy version 3.7.3 (no changes needed)
-- Jan Luebbe <jluebbe@debian.org> Sat, 29 Dec 2007 00:00:44 +0100
kvm (57+dfsg-2) unstable; urgency=low
* Build with alsa support (closes: #457536)
-- Jan Luebbe <jluebbe@debian.org> Sun, 23 Dec 2007 20:15:30 +0100
kvm (57+dfsg-1) unstable; urgency=low
* New upstream release (closes: #457061) - qemu has been updated to the current cvs version * Update upstream changelog
-- Jan Luebbe <jluebbe@debian.org> Thu, 20 Dec 2007 17:14:05 +0100
kvm (56+dfsg-1) unstable; urgency=low
* New upstream release * Update upstream changelog
-- Jan Luebbe <jluebbe@debian.org> Wed, 19 Dec 2007 20:27:19 +0100
kvm (55+dfsg-2) unstable; urgency=low
* Depend on libgnutls for VNC TLS support
* Build BIOS from kvm sources (kvm and qemu patchs are different, thanks to
Carlo Marcelo Arenas Belon for spotting this)
* Fix debian/rules clean
-- Jan Luebbe <jluebbe@debian.org> Sat, 08 Dec 2007 19:45:45 +0100
kvm (55+dfsg-1) unstable; urgency=low
* New upstream release * Include cpu information also for bugs against kvm-source * Update upstream changelog * Remove bios.bin from upstream tarball (closes: #452963) and depend on the current version of bochsbios
-- Jan Luebbe <jluebbe@debian.org> Fri, 07 Dec 2007 19:22:57 +0100
kvm (54+dfsg-1) unstable; urgency=low
* New upstream release
* Revive get-orig-source to remove other BIOS files (see #452963).
Thanks Soren Hansen.
* Include upstream changelog from the wiki.
* Update README.Debian and mention the kvm modules distributed with
the Linux kernel (closes: #440790)
-- Jan Luebbe <jluebbe@debian.org> Thu, 29 Nov 2007 14:40:23 +0000
kvm (53-1) unstable; urgency=low
* New upstream release * Upstream has removed the elpin BIOS files, stop repacking the tarball.
-- Jan Luebbe <jluebbe@debian.org> Wed, 21 Nov 2007 16:53:51 +0100
kvm (52+dfsg-1) unstable; urgency=low
* New upstream release * Switch to Vcs-Svn and Vcs-Browser in debian/control
-- Jan Luebbe <jluebbe@debian.org> Thu, 15 Nov 2007 18:47:41 +0100
kvm (48+dfsg-1) unstable; urgency=low
* Adopt package with Baruch Even's permission * New upstream release
-- Jan Luebbe <jluebbe@debian.org> Thu, 25 Oct 2007 11:15:54 +0200
kvm (46+dfsg-0.1) unstable; urgency=low
* Non-maintainer upload (low threshold nmu) * New upstream release * Adapt sf-get-orig-source from gnome-pkg-tools * Repackage tarball to remove elpin VGA bios (closes: #440472) * Add debian/watch file
-- Jan Luebbe <jluebbe@debian.org> Sun, 14 Oct 2007 12:02:54 +0200
kvm (36-0.1) unstable; urgency=low
* Non-maintainer upload (with permission) * New upstream release (closes: #438412) * Update patches * Install documentation from qemu to /usr/share/doc/kvm to avoid conflicts and refer to it from kvm(1) (closes: #434729) * Rename conflicting manpages * Add texi2html as a Build-Dependency * Make module-assistant a Dependency of kvm-source because it is needed by it's debian/rules * debian/conffiles is not necessary for /etc
-- Jan Luebbe <jluebbe@debian.org> Mon, 27 Aug 2007 18:45:36 +0200
kvm (28-4) unstable; urgency=low
* Divert kernel modules when installing the kvm-source modules
(Closes: #429851)
* kvm-ifup, even if bridge command failed continue to work, this will allow
users who have no bridge setup and intend to setup some other method to
get it to work without messing with the package files. (Closes: #407459)
-- Baruch Even <baruch@debian.org> Thu, 21 Jun 2007 12:37:54 +0100
kvm (28-3) unstable; urgency=low
* Fix infinite loop in kvm-ifup script
-- Baruch Even <baruch@debian.org> Mon, 18 Jun 2007 20:51:50 +0100
kvm (28-2) unstable; urgency=low
* We moved a file from kvm-source to kvm, to be able to properly upgrade we
specify a conflict against older versions (Closes: #417652)
* Fix kvm-ifup script to work in more conditions (Closes: #417151)
* Remove old /etc/udev/kvm.rules since it's not needed (Closes: #414331)
-- Baruch Even <baruch@debian.org> Sun, 17 Jun 2007 21:13:07 +0100
kvm (28-1) unstable; urgency=low
* New upstream release (Closes: #422197) - Should fix oops (Closes: #418928) * kqemu is no longer in non-free (Closes: #419152)
-- Baruch Even <baruch@debian.org> Sun, 17 Jun 2007 10:32:40 +0100
kvm (18-1) unstable; urgency=low
* New upstream release (Closes: #416926) * Move the module-assistant script to the kvm package from kvm-source so all users will benefit from the integration (Closes: #416122) * Remove patch to add qemu-ifup and kvm initscript, they are now part of kvm directly.
-- Baruch Even <baruch@debian.org> Sat, 31 Mar 2007 21:00:34 +0300
kvm (14-1) unstable; urgency=medium
[ Leonard Norrgård ]
* New upstream version. KVM is now based on qemu-0.9.0.
* Suggest etherboot and actually suggest hal (was only mentioning it).
* Update copyright info.
* Add a couple of patches from Debian qemu: 22_net_tuntap_stall.patch,
04_do_not_print_rtc_freq_if_ok.patch, 62_linux_boot_nasm.patch (62_*
currently only to avoid a buildd FTBS problem).
* Reorder the first two paragraphs in the description for kvm so the
general description is first, the more technical second.
* Moved adduser to Pre-Depends, as we rely on it for installation.
* For a detailed changelog, please see:
svn log -v -r 2227:2383 svn://svn.debian.org/svn/collab-maint/ext-maint/kvm/trunk
[ Baruch Even ]
* Update the uploader name of Leonard so that lintian won't think it's an
NMU.
* Add XS-Vcs-Browser field
-- Baruch Even <baruch@debian.org> Sat, 24 Feb 2007 17:43:42 +0200
kvm (13-1) UNRELEASED; urgency=low
* New upstream version.
-- Leonard Norrgård <vinsci@refactor.fi> Sat, 10 Feb 2007 07:40:59 +0200
kvm (12-1) unstable; urgency=high
* New upstream version. Most important upstream changes:
- Attempting to reboot Linux guest no longer reboots host on AMD,
actual guest reboot still not possible.
- The option -no-acpi is no longer required to install Windows
(the option is still recommended as the Windows ACPI HAL will
eat a lot of cpu time).
-- Leonard Norrgard <vinsci@refactor.fi> Sun, 23 Jan 2007 18:54:17 +0200
kvm (11-2) unstable; urgency=low
[ Baruch Even ]
* Make the quilt include part conditional so we don't have to have it when
building the kernel module. (Closes: #407447, #407482)
* Do not recommend linux-image-2.6 in kvm-source, and move linux-headers-2.6
from depends to suggests where it belongs. The package can build from
vanilla kernels as well as Debian kernels. (Closes: #407729)
[ Leonard Norrgard ]
* Enhance manual page a bit.
-- Baruch Even <baruch@debian.org> Sun, 21 Jan 2007 09:05:38 +0200
kvm (11-1) unstable; urgency=high
* New upstream version. Closes #406800, #406275, #404075.
* This version fixes many stability issues in earlier versions of KVM.
* Automatically create group kvm on installation of package kvm
* Added udev support to automatically set group kvm on /dev/kvm
* Added reportbug script (/usr/share/bug/kvm) so some info that
might be relevant gets included automatically.
* Tell module-assistant about the kvm-source package, so it shows up
in the module selection menu.
* Add information on building the modules using module-assistant.
* Add /etc/kvm/kvm-ifup script (conffile) to bring up the network for
the VM in a simpler way, see the manual page for kvm for description.
This used to be /etc/qemu-ifup, as installed by the qemu package.
* Depend on iproute, bridge-utils, used by kvm-ifup and the upcoming
/etc/init.d script.
* Remove non-x86 bios images - KVM is only meaningful for x86 guests.
* Keep KVM bios files in /usr/share/kvm, rather than sharing them with
other packages as the KVM bios is different (also avoids unexpected
bios updates).
* Don't depend on qemu, as we now keep our own bios.
* Recommend kvm-source, qemu (mostly for qemu-img), vde2 and linux-image-2.6.
* Suggest sudo and debootstrap.
* For kvm-source, depend on linux-headers-2.6 | linux-source-2.6,
recommend linux-image-2.6 and suggest module-assistant and
kernel-package.
* Use quilt to handle patches.
* More detailed package description for kvm, added Homepage:.
-- Leonard Norrgard <vinsci@refactor.fi> Sun, 14 Jan 2007 07:11:03 +0200
2006
kvm (7-1) unstable; urgency=low
* New upstream version * Install the Intel and AMD modules (Closes: 402820)
-- Baruch Even <baruch@debian.org> Wed, 13 Dec 2006 09:19:44 +0200
kvm (5-2) unstable; urgency=low
* Yet another attempt to fix building on amd64.
-- Baruch Even <baruch@debian.org> Wed, 6 Dec 2006 08:35:04 +0200
kvm (5-1) unstable; urgency=low
* New upstream version * Really fix building on amd64 (Closes: #400549)
-- Baruch Even <baruch@debian.org> Wed, 6 Dec 2006 07:12:30 +0200
kvm (4-2) unstable; urgency=low
* Allow build on amd64 arch, it really should mean Intel x86 64bit arches,
kvm still doesn't support AMD SVM instructions and requires the Intel
CPUs. (Closes: #400549)
-- Baruch Even <baruch@debian.org> Tue, 28 Nov 2006 22:16:08 +0200
kvm (4-1) unstable; urgency=low
* New upstream version.
-- Baruch Even <baruch@debian.org> Tue, 21 Nov 2006 22:23:26 +0200
kvm (3-2) unstable; urgency=low
* Use KERNEL_DIR variable when building the module to enable building a
module for a kernel that is not being run right now. (Closes: #399603)
* Add manpage that refers the user to qemu(1) where he can find all the
information he needs.
-- Baruch Even <baruch@debian.org> Tue, 21 Nov 2006 09:22:57 +0200
kvm (3-1) unstable; urgency=low
* New upstream version. * Use upstream versioning of natural numbers. * First upload to Debian (Closes: #398458)
-- Baruch Even <baruch@debian.org> Wed, 15 Nov 2006 23:58:12 +0200
kvm (0.0.2-1) unstable; urgency=low
* Initial release
-- Baruch Even <baruch@debian.org> Tue, 14 Nov 2006 20:49:57 +0200