CVE-2019-12155
Summary
| CVE | CVE-2019-12155 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-24 16:29:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference. |
Risk And Classification
Problem Types: CWE-476
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 1927-1] qemu security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 30 Update: qemu-3.1.0-9.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [SECURITY] Fedora 29 Update: qemu-3.0.1-4.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| git.qemu.org Git - qemu.git/commit | git.qemu.org | ||
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [SECURITY] Fedora 29 Update: qemu-3.0.1-4.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security-announce] openSUSE-SU-2019:2041-1: important: Security update | SUSE | lists.opensuse.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| oss-security - CVE-2019-12155 QEMU: qxl: null pointer dereference while releasing spice resources | CONFIRM | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| git.qemu.org Git - qemu.git/commit | MISC | git.qemu.org | |
| [SECURITY] Fedora 30 Update: qemu-3.1.0-9.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [security-announce] openSUSE-SU-2019:2059-1: important: Security update | SUSE | lists.opensuse.org | |
| USN-4191-1: QEMU vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [Qemu-devel] [PULL 1/8] qxl: check release info object | MISC | lists.gnu.org | Mailing List, Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4454-1 qemu | DEBIAN | www.debian.org | |
| USN-4191-2: QEMU vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| Bugtraq: [SECURITY] [DSA 4454-1] qemu security update | BUGTRAQ | seclists.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159660 Oracle Enterprise Linux Security Update for virt:ol (ELSA-2019-3345)
- 377317 Alibaba Cloud Linux Security Update for qemu-kvm (ALINUX2-SA-2019:0051)
- 377373 Alibaba Cloud Linux Security Update for virt:rhel (ALINUX3-SA-2022:0074)
- 377413 Alibaba Cloud Linux Security Update for virt:rhel and virt-devel:rhel (ALINUX3-SA-2022:0119)
- 940336 AlmaLinux Security Update for virt:rhel (ALSA-2019:3345)
- 960798 Rocky Linux Security Update for virt:rhel (RLSA-2019:3345)