CVE-2019-12068

Description

In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances s->dsp index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.

Risk Information

Base Score
3.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS Score
Exploitation Probability
0.086

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2019-12068 are affected in QEMU 14.1Windows
Machine emulator and virtualizer (USN-4191-1) qemu_3.1+dfsg-2ubuntu3.6_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_3.1+dfsg-2ubuntu3.6_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_4.0+dfsg-0ubuntu9.1_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_4.0+dfsg-0ubuntu9.1_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_2.5+dfsg-5ubuntu10.42_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu_2.5+dfsg-5ubuntu10.42_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_3.1+dfsg-2ubuntu3.6_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_3.1+dfsg-2ubuntu3.6_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_4.0+dfsg-0ubuntu9.1_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_4.0+dfsg-0ubuntu9.1_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_2.5+dfsg-5ubuntu10.42_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system_2.5+dfsg-5ubuntu10.42_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_3.1+dfsg-2ubuntu3.6_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_3.1+dfsg-2ubuntu3.6_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_4.0+dfsg-0ubuntu9.1_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_4.0+dfsg-0ubuntu9.1_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_2.5+dfsg-5ubuntu10.42_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_2.5+dfsg-5ubuntu10.42_amd64.debLinux
qemu security update(DSA-4665-1) qemu_3.1+dfsg-8+deb10u5_i386.debLinux
qemu security update(DSA-4665-1) qemu_3.1+dfsg-8+deb10u5_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-kvm_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-kvm_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-utils_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-utils_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user-static_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-user-static_2.11+dfsg-1ubuntu7.20_amd64.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system-common_2.11+dfsg-1ubuntu7.20_i386.debLinux
Machine emulator and virtualizer (USN-4191-1) qemu-system-common_2.11+dfsg-1ubuntu7.20_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234