From ${URL} : When guest sends udp packet with source port and source addr 0, uninitialized socket is picked up when looking for matching and already created udp sockets, and later passed to sosendto() where NULL pointer dereference is hit during so->slirp->vnetwork_mask.s_addr access. Only guests using qemu user networking are affected. Upstream patch submission: http://lists.nongnu.org/archive/html/qemu-devel/2014-09/msg03543.html @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Setting Whiteboard back to ebuild, as 2.1.2 not in tree.
Commit message: Version bump http://sources.gentoo.org/app-emulation/qemu/qemu-2.1.2.ebuild?rev=1.1
Added to existing GLSA draft
This issue was resolved and addressed in GLSA 201412-01 at http://security.gentoo.org/glsa/glsa-201412-01.xml by GLSA coordinator Kristian Fiskerstrand (K_F).