CVE-2019-5008NULL Pointer Dereference in Qemu

Severity
7.5HIGHNVD
OSV5.6
EPSS
1.2%
top 21.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 19
Latest updateMay 24

Description

hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/qemu< qemu 1:3.1+dfsg-8 (bookworm)
Debianqemu/qemu< 1:3.1+dfsg-8+3
Ubuntuqemu/qemu< 2.0.0+dfsg-2ubuntu1.46+2
NVDqemu/qemu3.1.50

Patches

🔴Vulnerability Details

3
GHSA
GHSA-764p-23v8-xg3p: hw/sparc64/sun4u2022-05-24
OSV
qemu update2019-05-14
OSV
CVE-2019-5008: hw/sparc64/sun4u2019-04-19

📋Vendor Advisories

3
Ubuntu
QEMU update2019-05-14
Red Hat
QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS2019-01-04
Debian
CVE-2019-5008: qemu - hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, w...2019

💬Community

4
Bugzilla
CVE-2019-5008 xen: QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]2019-06-28
Bugzilla
CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [epel-7]2019-05-03
Bugzilla
CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]2019-05-03
Bugzilla
CVE-2019-5008 QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS2019-05-03