CVE-2019-12068
Summary
| CVE | CVE-2019-12068 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-24 20:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well. |
Risk And Classification
Problem Types: CWE-835
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Application | Qemu | Qemu | 1 | 2.1+dfsg-12+deb8u6 | All | All |
| Application | Qemu | Qemu | 1 | 2.8+dfsg-6+deb9u8 | All | All |
| Application | Qemu | Qemu | 1 | 3.1+dfsg-8+deb10u2 | All | All |
| Application | Qemu | Qemu | 1 | 3.1+dfsg-8~deb10u1 | All | All |
| Application | Qemu | Qemu | 1 | 4.1-1 | All | All |
| Application | Qemu | Qemu | 1\ | 2.1\+dfsg-12\+deb8u6 | All | All |
| Application | Qemu | Qemu | 1\ | 2.8\+dfsg-6\+deb9u8 | All | All |
| Application | Qemu | Qemu | 1\ | 3.1\+dfsg-8\+deb10u2 | All | All |
| Application | Qemu | Qemu | 1\ | 3.1\+dfsg-8\~deb10u1 | All | All |
| Application | Qemu | Qemu | 1\ | 4.1-1 | All | All |
| Application | Qemu | Qemu | 1\ | 2.1\+dfsg-12\+deb8u6 | All | All |
| Application | Qemu | Qemu | 1\ | 2.8\+dfsg-6\+deb9u8 | All | All |
| Application | Qemu | Qemu | 1\ | 3.1\+dfsg-8\+deb10u2 | All | All |
| Application | Qemu | Qemu | 1\ | 3.1\+dfsg-8\~deb10u1 | All | All |
| Application | Qemu | Qemu | 1\ | 4.1-1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 1927-1] qemu security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2510-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| git.qemu.org Git - qemu.git/commit | MISC | git.qemu.org | Mailing List, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2505-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| [SECURITY] [DLA 2288-1] qemu security update | MLIST | lists.debian.org | |
| CVE-2019-12068 | MISC | security-tracker.debian.org | Third Party Advisory |
| [Qemu-devel] [PATCH v3 1/2] scsi: lsi: exit infinite loop while executin | MISC | lists.gnu.org | Mailing List, Patch, Third Party Advisory |
| USN-4191-1: QEMU vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| Debian -- Security Information -- DSA-4665-1 qemu | DEBIAN | www.debian.org | |
| git.qemu.org Git - qemu.git/commit | git.qemu.org | ||
| USN-4191-2: QEMU vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.