CVE-2019-12067

Aliases:UBUNTU-CVE-2019-12067DEBIAN-CVE-2019-12067CGA-3wcq-q8gx-6pjqCGA-446v-672m-8h27CGA-466m-9vcj-m8x2CGA-4vmj-p44c-gf7hCGA-526f-3ghw-wjv2CGA-53fc-7v74-xwpfCGA-5hg2-2fwc-xpfjCGA-6cjv-772w-jqw5CGA-74hr-37w9-4vf8CGA-9hvr-fh7h-j767CGA-9r4x-86p3-w3r8CGA-c434-cpjp-wxx4CGA-cm3j-m6r9-67vxCGA-fpf4-7jr2-c6v9CGA-gg3p-ff68-2p63CGA-hrjp-cq9c-g938CGA-jhqg-q7j6-xgj8CGA-jwpw-q596-5539CGA-mx9m-x5g3-4q5wCGA-pcjj-gjfq-8q5qCGA-pf8q-j6r8-9qqrCGA-r34h-h73g-h67rCGA-r556-36c8-m4wjCGA-vgc3-g39v-8gf3CGA-vgvc-wvmm-8cmcCGA-wc86-79x3-w8pxCGA-x824-w8hv-42xfCGA-xg69-m2qv-68hx
Modified
Published: 02 Jun 2021, 14:18
Last modified:04 Aug 2024, 23:10

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.31% LOW
0% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Jun 2021, 14:18
Published
Vulnerability first disclosed
04 Aug 2024, 23:10
Last Modified
Vulnerability information updated

Description

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.31% Percentile: 24%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • chainguardqemu

    all

  • chainguardqemu-block-iscsi

    all

  • chainguardqemu-block-rbd

    all

  • chainguardqemu-edk2-aarch64

    all

  • chainguardqemu-edk2-x86_64

    all

  • chainguardqemu-ipxe

    all

  • chainguardqemu-modules

    all

  • chainguardqemu-modules-spice

    all

  • chainguardqemu-modules-usb-host

    all

  • chainguardqemu-system-aarch64

    all

  • chainguardqemu-system-x86_64

    all

  • chainguardqemu-user

    all

  • chainguardqemu-user-binfmt

    all

  • chainguardqemu-utils

    all

  • wolfiqemu

    all

  • wolfiqemu-block-iscsi

    all

  • wolfiqemu-block-rbd

    all

  • wolfiqemu-edk2-aarch64

    all

  • wolfiqemu-edk2-x86_64

    all

  • wolfiqemu-ipxe

    all

  • wolfiqemu-modules

    all

  • wolfiqemu-modules-spice

    all

  • wolfiqemu-modules-usb-host

    all

  • wolfiqemu-system-aarch64

    all

  • wolfiqemu-system-x86_64

    all

  • wolfiqemu-user

    all

  • wolfiqemu-user-binfmt

    all

  • wolfiqemu-utils

    all

  • debianqemu

    all | all | all | all

  • ubuntuqemu

    all | all | all | all | all

  • ubuntuqemu-hwe

    all

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    30

  • qemuqemu

    na

  • redhatenterprise_linux

    8.0

  • redhatopenstack_platform

    10.0 | 14.0

References (7)