CVE-2019-12068
Last modified
CVE-2019-12068 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Qemu | Qemu | 1\ | 4.1-1 |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 18.04 | — |
| Canonical | Ubuntu Linux | 19.04 | — |
| Canonical | Ubuntu Linux | 19.10 | — |
| Opensuse | Leap | 15.0 | — |
| Opensuse | Leap | 15.1 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00021.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.htmlMailing List, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2019-12068Third Party Advisory
- https://usn.ubuntu.com/4191-1/Third Party Advisory
- https://usn.ubuntu.com/4191-2/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00021.htmlMailing List, Third Party Advisory
- https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.htmlMailing List, Patch, Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2019-12068Third Party Advisory
- https://usn.ubuntu.com/4191-1/Third Party Advisory
- https://usn.ubuntu.com/4191-2/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12068?
How severe is CVE-2019-12068?
How do I fix CVE-2019-12068?
Are you affected by CVE-2019-12068?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
