CVE-2019-12067
Aliases:UBUNTU-CVE-2019-12067DEBIAN-CVE-2019-12067CGA-3wcq-q8gx-6pjqCGA-446v-672m-8h27CGA-466m-9vcj-m8x2CGA-4vmj-p44c-gf7hCGA-526f-3ghw-wjv2CGA-53fc-7v74-xwpfCGA-5hg2-2fwc-xpfjCGA-6cjv-772w-jqw5CGA-74hr-37w9-4vf8CGA-9hvr-fh7h-j767CGA-9r4x-86p3-w3r8CGA-c434-cpjp-wxx4CGA-cm3j-m6r9-67vxCGA-fpf4-7jr2-c6v9CGA-gg3p-ff68-2p63CGA-hrjp-cq9c-g938CGA-jhqg-q7j6-xgj8CGA-jwpw-q596-5539CGA-mx9m-x5g3-4q5wCGA-pcjj-gjfq-8q5qCGA-pf8q-j6r8-9qqrCGA-r34h-h73g-h67rCGA-r556-36c8-m4wjCGA-vgc3-g39v-8gf3CGA-vgvc-wvmm-8cmcCGA-wc86-79x3-w8pxCGA-x824-w8hv-42xfCGA-xg69-m2qv-68hx
Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 02 Jun 2021, 14:18
Last modified:04 Aug 2024, 23:10
Vulnerability Summary
Overall Risk (default)
medium
26/100 CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.31% LOW
0% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
02 Jun 2021, 14:18
Published
Vulnerability first disclosed
04 Aug 2024, 23:10
Last Modified
Vulnerability information updated
Description
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.31%• Percentile: 24%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- chainguard•qemu
all
- chainguard•qemu-block-iscsi
all
- chainguard•qemu-block-rbd
all
- chainguard•qemu-edk2-aarch64
all
- chainguard•qemu-edk2-x86_64
all
- chainguard•qemu-ipxe
all
- chainguard•qemu-modules
all
- chainguard•qemu-modules-spice
all
- chainguard•qemu-modules-usb-host
all
- chainguard•qemu-system-aarch64
all
- chainguard•qemu-system-x86_64
all
- chainguard•qemu-user
all
- chainguard•qemu-user-binfmt
all
- chainguard•qemu-utils
all
- wolfi•qemu
all
- wolfi•qemu-block-iscsi
all
- wolfi•qemu-block-rbd
all
- wolfi•qemu-edk2-aarch64
all
- wolfi•qemu-edk2-x86_64
all
- wolfi•qemu-ipxe
all
- wolfi•qemu-modules
all
- wolfi•qemu-modules-spice
all
- wolfi•qemu-modules-usb-host
all
- wolfi•qemu-system-aarch64
all
- wolfi•qemu-system-x86_64
all
- wolfi•qemu-user
all
- wolfi•qemu-user-binfmt
all
- wolfi•qemu-utils
all
- debian•qemu
all | all | all | all
- ubuntu•qemu
all | all | all | all | all
- ubuntu•qemu-hwe
all
- debian•debian_linux
9.0 | 10.0 | 11.0
- fedoraproject•fedora
30
- qemu•qemu
na
- redhat•enterprise_linux
8.0
- redhat•openstack_platform
10.0 | 14.0
References (7)
- https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01358.html
- https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01487.html
- https://bugzilla.suse.com/show_bug.cgi?id=1145642
- https://security-tracker.debian.org/tracker/CVE-2019-12067
- https://security.netapp.com/advisory/ntap-20210727-0001/
- https://ubuntu.com/security/CVE-2019-12067
- https://www.cve.org/CVERecord?id=CVE-2019-12067