CVE-2019-12068
published 2019-09-24CVE-2019-12068: In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing…
PriorityP413low3.8CVSS 3.1
AVLACLPRLUINSCCNINAL
EPSS
0.51%
40.1th percentile
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | qemu | < qemu 1:4.1-2 (bookworm) | qemu 1:4.1-2 (bookworm) |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.42 | 1:2.5+dfsg-5ubuntu10.42 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.20 | 1:2.11+dfsg-1ubuntu7.20 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.47 | 2.0.0+dfsg-2ubuntu1.47 |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv3.8LOW
vendor_debian3.8LOW
vendor_redhat3.8LOW
vendor_ubuntu3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4699-632x-4vxr: In QEMU 1:4
ghsa_unreviewed·2022-05-24
CVE-2019-12068 [LOW] CWE-835 GHSA-4699-632x-4vxr: In QEMU 1:4
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
OSV
qemu vulnerabilities
osv·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] qemu vulnerabilities
qemu vulnerabilities
USN-4191-2 fixed a vulnerability in QEMU. This update provides the
corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local attacker could possibly use this
to bypass ACL restrictions. (CV
OSV
qemu vulnerabilities
osv·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] qemu vulnerabilities
qemu vulnerabilities
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local attacker could possibly use this
to bypass ACL restrictions. (CVE-2019-13164)
It was discovered that a heap-based buffer overflow existed in the SLiRP
networking implementation of QEMU. A local attacker
OSV
CVE-2019-12068: In QEMU 1:4
osv·2019-09-24·CVSS 3.8
CVE-2019-12068 [LOW] CVE-2019-12068: In QEMU 1:4
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
USN-4191-2 fixed a vulnerability in QEMU. This update provides the
corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local att
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2019-11-14·CVSS 3.8
CVE-2019-12068 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
It was discovered that the LSI SCSI adapter emulator implementation in QEMU
did not properly validate executed scripts. A local attacker could use this
to cause a denial of service. (CVE-2019-12068)
Sergej Schumilo, Cornelius Aschermann and Simon Wörner discovered that the
qxl paravirtual graphics driver implementation in QEMU contained a null
pointer dereference. A local attacker in a guest could use this to cause a
denial of service. (CVE-2019-12155)
Riccardo Schirone discovered that the QEMU bridge helper did not properly
validate network interface names. A local attacker could possibly use this
to bypass ACL restrictions. (CVE-2019-13164)
It was discovered that a heap-based buffer overflow existed in
Red Hat
qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script
vendor_redhat·2019-08-14·CVSS 3.8
CVE-2019-12068 [LOW] CWE-835 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script
qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
A flaw was found in QEMU's LSI53C895A device emulator. When executing LSI scripts, a crafted sequence of I/O requests may cause the emulator to enter into an infinite loop. This vulnerability could be executed locally and would affect the availability of the system.
Statement: The qemu-kvm package
Debian
CVE-2019-12068: qemu - In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1...
vendor_debian·2019·CVSS 3.8
CVE-2019-12068 [LOW] CVE-2019-12068: qemu - In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1...
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
Scope: local
bookworm: resolved (fixed in 1:4.1-2)
bullseye: resolved (fixed in 1:4.1-2)
forky: resolved (fixed in 1:4.1-2)
sid: resolved (fixed in 1:4.1-2)
trixie: resolved (fixed in 1:4.1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12068 xen: qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [fedora-all]
bugzilla·2019-12-12·CVSS 3.8
CVE-2019-12068 [LOW] CVE-2019-12068 xen: qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [fedora-all]
CVE-2019-12068 xen: qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [epel-7]
bugzilla·2019-11-18·CVSS 3.8
CVE-2019-12068 [LOW] CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [epel-7]
CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the foll
Bugzilla
CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [fedora-all]
bugzilla·2019-11-18·CVSS 3.8
CVE-2019-12068 [LOW] CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [fedora-all]
CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script
bugzilla·2019-11-18·CVSS 3.8
CVE-2019-12068 [LOW] CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script
CVE-2019-12068 qemu: scsi: lsi: potential infinite loop when executing script in lsi_execute_script
Qemu emulator built with the LSI53C895A SCSI Host Bus Adapter emulation support
is vulnerable to an infinite loop issue. It could occur when executing a script
in lsi_execute_script(). The LSI scsi adapter emulator advances 's->dsp' index
to read next opcode. This can lead to an infinite loop if the next opcode is
empty.
A privileged user inside guest could use this flaw to consume CPU cycles on
the host resulting in DoS scenario.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commit;h=de594e47659029316bbf9391efb79da0a1a08e08
Discussion:
Created qemu tracking bugs for this issue:
Affects: epel-7 [bug 1773751]
Affects: fedora-all [bug 1773750]
---
The device is not included in
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.htmlhttps://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=de594e47659029316bbf9391efb79da0a1a08e08https://lists.debian.org/debian-lts-announce/2019/09/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.htmlhttps://security-tracker.debian.org/tracker/CVE-2019-12068https://usn.ubuntu.com/4191-1/https://usn.ubuntu.com/4191-2/https://www.debian.org/security/2020/dsa-4665http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.htmlhttps://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=de594e47659029316bbf9391efb79da0a1a08e08https://lists.debian.org/debian-lts-announce/2019/09/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.htmlhttps://security-tracker.debian.org/tracker/CVE-2019-12068https://usn.ubuntu.com/4191-1/https://usn.ubuntu.com/4191-2/https://www.debian.org/security/2020/dsa-4665
2019-09-24
Published