CVE-2019-6501
published 2019-03-21CVE-2019-6501: In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.56%
42.6th percentile
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qemu | < qemu 1:3.1+dfsg-3 (bookworm) | qemu 1:3.1+dfsg-3 (bookworm) |
| fedoraproject | fedora | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 1:3.1+dfsg-3 | 1:3.1+dfsg-3 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-3 | 1:3.1+dfsg-3 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-3 | 1:3.1+dfsg-3 |
| qemu | qemu | >= 0 < 1:3.1+dfsg-3 | 1:3.1+dfsg-3 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rhjv-54vx-5mjg: In QEMU 3
ghsa_unreviewed·2022-05-14
CVE-2019-6501 [MEDIUM] CWE-125 GHSA-rhjv-54vx-5mjg: In QEMU 3
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
OSV
CVE-2019-6501: In QEMU 3
osv·2019-03-21·CVSS 5.5
CVE-2019-6501 [MEDIUM] CVE-2019-6501: In QEMU 3
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
Red Hat
QEMU: scsi-generic: possible OOB access while handling inquiry request
vendor_redhat·2019-01-11·CVSS 5.5
CVE-2019-6501 [MEDIUM] CWE-787 QEMU: scsi-generic: possible OOB access while handling inquiry request
QEMU: scsi-generic: possible OOB access while handling inquiry request
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 7) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 8) - Not affected
Package: qemu-kvm-rhev (Red Hat OpenStack Platform 8 (Liberty)) - Fix deferred
Package: qemu-kvm-rhev (Red Hat OpenStack Platform 9 (Mitaka)) - Fix deferred
Debian
CVE-2019-6501: qemu - In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-b...
vendor_debian·2019·CVSS 5.5
CVE-2019-6501 [MEDIUM] CVE-2019-6501: qemu - In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-b...
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
Scope: local
bookworm: resolved (fixed in 1:3.1+dfsg-3)
bullseye: resolved (fixed in 1:3.1+dfsg-3)
forky: resolved (fixed in 1:3.1+dfsg-3)
sid: resolved (fixed in 1:3.1+dfsg-3)
trixie: resolved (fixed in 1:3.1+dfsg-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11772 IBM JDK: Out-of-bounds access in the String.getBytes method
bugzilla·2019-08-07·CVSS 9.8
CVE-2019-11772 [CRITICAL] CVE-2019-11772 IBM JDK: Out-of-bounds access in the String.getBytes method
CVE-2019-11772 IBM JDK: Out-of-bounds access in the String.getBytes method
IBM JDK 8 SR5 FP40 (8.0.5.40) fixes a flaw described by upstream as:
Eclipse OpenJ9 could allow a local attacker to gain elevated privileges on the system, caused by an out-of-bounds write in the String.getBytes method. An attacker could exploit this vulnerability to corrupt memory and write to any 32-bit address or beyond the end of a byte array within Java code run under a SecurityManager.
OpenJ9 upstream bug:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=549075
OpenJ9 upstream merge request and commit:
https://github.com/eclipse/openj9/pull/6501
https://github.com/eclipse/openj9/commit/426e321c22c76a157312d862acc6b14114b51f95
References:
https://www-01.ibm.com/support/docview.wss?uid=ibm10960422
https://d
Bugzilla
CVE-2019-6501 qemu: scsi-generic: possible OOB access while handling inquiry request [fedora-all]
bugzilla·2019-01-24·CVSS 5.5
CVE-2019-6501 [MEDIUM] CVE-2019-6501 qemu: scsi-generic: possible OOB access while handling inquiry request [fedora-all]
CVE-2019-6501 qemu: scsi-generic: possible OOB access while handling inquiry request [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2019-6501 QEMU: scsi-generic: possible OOB access while handling inquiry request
bugzilla·2019-01-22·CVSS 5.5
CVE-2019-6501 [MEDIUM] CVE-2019-6501 QEMU: scsi-generic: possible OOB access while handling inquiry request
CVE-2019-6501 QEMU: scsi-generic: possible OOB access while handling inquiry request
An out of bounds r/w access issue was found in the way QEMU
handled inquiry request coming from a guest in scsi_handle_inquiry_reply().
A guest user/process could use this flaw to corrupt byte of QEMU process
memory.
Upstream patch:
-> https://lists.gnu.org/archive/html/qemu-devel/2019-01/msg02324.html
Reference:
-> https://www.openwall.com/lists/oss-security/2019/01/24/1
Discussion:
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1669005]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2166 https://access.redhat.com/errata/RHSA-2019:2166
---
This bug is now closed. Further updates for individual products will be reflecte
http://www.openwall.com/lists/oss-security/2019/01/24/1https://access.redhat.com/errata/RHSA-2019:2166https://access.redhat.com/errata/RHSA-2019:2425https://access.redhat.com/errata/RHSA-2019:2553https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJMTVGDLA654HNCDGLCUEIP36SNJEKK7/https://lists.gnu.org/archive/html/qemu-devel/2019-01/msg02324.htmlhttps://security.netapp.com/advisory/ntap-20190411-0006/http://www.openwall.com/lists/oss-security/2019/01/24/1https://access.redhat.com/errata/RHSA-2019:2166https://access.redhat.com/errata/RHSA-2019:2425https://access.redhat.com/errata/RHSA-2019:2553https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJMTVGDLA654HNCDGLCUEIP36SNJEKK7/https://lists.gnu.org/archive/html/qemu-devel/2019-01/msg02324.htmlhttps://security.netapp.com/advisory/ntap-20190411-0006/
2019-03-21
Published