CVE-2019-5008
published 2019-04-19CVE-2019-5008: hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.82%
85.1th percentile
hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:3.1+dfsg-8 (bookworm) | qemu 1:3.1+dfsg-8 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:3.1+dfsg-8 | 1:3.1+dfsg-8 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-8 | 1:3.1+dfsg-8 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-8 | 1:3.1+dfsg-8 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-8 | 1:3.1+dfsg-8 |
| qemu | qemu | >= 0 < 2.0.0+dfsg-2ubuntu1.46 | 2.0.0+dfsg-2ubuntu1.46 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.38 | 1:2.5+dfsg-5ubuntu10.38 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.13 | 1:2.11+dfsg-1ubuntu7.13 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-764p-23v8-xg3p: hw/sparc64/sun4u
ghsa_unreviewed·2022-05-24
CVE-2019-5008 [HIGH] CWE-476 GHSA-764p-23v8-xg3p: hw/sparc64/sun4u
hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
OSV
qemu update
osv·2019-05-14·CVSS 5.6
[MEDIUM] qemu update
qemu update
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi, Herbert Bos, and Cristiano Giuffrida discovered that memory
previously stored in microarch
OSV
CVE-2019-5008: hw/sparc64/sun4u
osv·2019-04-19·CVSS 7.5
CVE-2019-5008 [HIGH] CVE-2019-5008: hw/sparc64/sun4u
hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
Ubuntu
QEMU update
vendor_ubuntu·2019-05-14·CVSS 5.6
CVE-2018-12126 [MEDIUM] QEMU update
Title: QEMU update
Summary: Several issues were addressed in QEMU.
Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Giorgi Maisuradze, Dan
Horea Lutas, Andrei Lutas, Volodymyr Pikhur, Stephan van Schaik, Alyssa
Milburn, Sebastian Österlund, Pietro Frigo, Kaveh Razavi, Herbert Bos,
Cristiano Giuffrida, Moritz Lipp, Michael Schwarz, and Daniel Gruss
discovered that memory previously stored in microarchitectural fill buffers
of an Intel CPU core may be exposed to a malicious process that is
executing on the same CPU core. A local attacker could use this to expose
sensitive information. (CVE-2018-12130)
Brandon Falk, Ke Sun, Henrique Kawakami, Kekai Hu, Rodrigo Branco, Stephan
van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo, Kaveh
Razavi, Herbert Bos, and Cristiano Giuffri
Red Hat
QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS
vendor_redhat·2019-01-04·CVSS 7.5
CVE-2019-5008 [HIGH] CWE-476 QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS
QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS
hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-ma (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 8) - Not affected
Package: qemu-kvm-rhev (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Package: qemu-kvm-rhev (Red Hat OpenStack
Debian
CVE-2019-5008: qemu - hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, w...
vendor_debian·2019·CVSS 7.5
CVE-2019-5008 [HIGH] CVE-2019-5008: qemu - hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, w...
hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a denial of service via a device driver.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-8)
bullseye: resolved (fixed in 1:3.1+dfsg-8)
forky: resolved (fixed in 1:3.1+dfsg-8)
sid: resolved (fixed in 1:3.1+dfsg-8)
trixie: resolved (fixed in 1:3.1+dfsg-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5008 xen: QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]
bugzilla·2019-06-28·CVSS 7.5
CVE-2019-5008 [HIGH] CVE-2019-5008 xen: QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]
CVE-2019-5008 xen: QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [epel-7]
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-5008 [HIGH] CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [epel-7]
CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to
Bugzilla
CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-5008 [HIGH] CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]
CVE-2019-5008 qemu: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2019-5008 QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS
bugzilla·2019-05-03·CVSS 7.5
CVE-2019-5008 [HIGH] CVE-2019-5008 QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS
CVE-2019-5008 QEMU: NULL pointer dereference in hw/sparc64/sun4u.c leading to DoS
A NULL pointer dereference issue was found in the UltraSPARC PC-like (Sun4u)
machine emulator of QEMU. It could occur if a driver called mmio read function, allowing an attacker to cause a denial of service.
Upstream patch:
-> https://git.qemu.org/?p=qemu.git;a=commitdiff;h=ad280559c68360c9f1cd7be063857853759e6a73
Reference:
-> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=927439
Discussion:
Created qemu tracking bugs for this issue:
Affects: epel-7 [bug 1705917]
Affects: fedora-all [bug 1705916]
---
Acknowledgments:
Name: Fakhri Zulkifli
---
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1725030]
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.htmlhttp://www.securityfocus.com/bid/108024https://fakhrizulkifli.github.io/posts/2019/01/03/CVE-2019-5008/https://git.qemu.org/?p=qemu.git%3Ba=history%3Bf=hw/sparc64/sun4u.c%3Bhb=HEADhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BOE3PVFPMWMXV3DGP2R3XIHAF2ZQU3FS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVDHJB2QKXNDU7OFXIHIL5O5VN5QCSZL/https://usn.ubuntu.com/3978-1/http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00000.htmlhttp://www.securityfocus.com/bid/108024https://fakhrizulkifli.github.io/posts/2019/01/03/CVE-2019-5008/https://git.qemu.org/?p=qemu.git%3Ba=history%3Bf=hw/sparc64/sun4u.c%3Bhb=HEADhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BOE3PVFPMWMXV3DGP2R3XIHAF2ZQU3FS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RVDHJB2QKXNDU7OFXIHIL5O5VN5QCSZL/https://usn.ubuntu.com/3978-1/
2019-04-19
Published