From ${URL} : Qemu emulator built with the VNC display driver is vulnerable to an infinite loop issue. It could occur while processing a CLIENT_CUT_TEXT message with specially crafted payload message. A privileged guest user could use this flaw to crash the Qemu process on the host, resulting in DoS. Upstream fix: ------------- -> http://git.qemu.org/?p=qemu.git;a=commit;h=f9a70e79391f6d7c2a912d785239ee8effc1922d @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
that fix is in qemu-2.1.0. not sure why they've gone and posted an announce now (over a year later) and requested a CVE for it.