CVE-2019-12155NULL Pointer Dereference in Qemu

Severity
7.5HIGHNVD
OSV3.8
EPSS
1.1%
top 21.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 24
Latest updateMay 24

Description

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/qemu< qemu 1:3.1+dfsg-8 (bookworm)
Debianqemu/qemu< 1:3.1+dfsg-8+3
Ubuntuqemu/qemu< 1:2.5+dfsg-5ubuntu10.42+2
NVDqemu/qemu4.0.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-96vp-7vcr-rp4h: interface_release_resource in hw/display/qxl2022-05-24
OSV
qemu vulnerabilities2019-11-14
OSV
qemu vulnerabilities2019-11-14
OSV
CVE-2019-12155: interface_release_resource in hw/display/qxl2019-05-24

📋Vendor Advisories

4
Ubuntu
QEMU vulnerabilities2019-11-14
Ubuntu
QEMU vulnerabilities2019-11-14
Red Hat
QEMU: qxl: null pointer dereference while releasing spice resources2019-04-25
Debian
CVE-2019-12155: qemu - interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a...2019

💬Community

3
Bugzilla
CVE-2019-12155 qemu: qxl: null pointer dereference while releasing spice resources [fedora-all]2019-05-22
Bugzilla
CVE-2019-12155 QEMU: qxl: null pointer dereference while releasing spice resources2019-05-22
Bugzilla
CVE-2019-12155 qemu: qxl: null pointer dereference while releasing spice resources [fedora-all]2019-05-22