USN-3560-1: QEMU update Ubuntu Security Notice USN-3560-1 7th February, 2018 qemu update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Spectre mitigations were added to QEMU. Software description qemu – Machine emulator and virtualizer Details It was discovered that microprocessors utilizing speculative executionand branch prediction may allow unauthorized memory reads via sidechannelattacks. This flaw is known as Spectre. An attacker in the guest could usethis to expose sensitive guest information, including kernel memory. This update allows QEMU to expose new CPU features added by microcodeupdates to guests on amd64, i386, and s390x. On amd64 and i386, new CPUmodels that match the updated microcode features were added with an -IBRSsuffix. Certain environments will require guests to be switched manually tothe new CPU models after microcode updates have been applied [ more… ]