CVE-2019-12067: Null Pointer Dereference
Published Jun 2, 2021
·Updated
The ahcicommitbuf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->curcmd' is null.
Affected Software
10 affected components
Qemu Qemu
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=30
redhat Openstack Platform=10.0
redhat Openstack Platform=14.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=8.0
debian/qemu<=1:5.2+dfsg-11+deb11u3, <=1:5.2+dfsg-11+deb11u5, <=1:7.2+dfsg-7+deb12u18, <=1:7.2+dfsg-7+deb12u15, <=1:10.0.7+ds-0+deb13u1, <=1:10.0.2+ds-2+deb13u1, <=1:10.2.0+ds-2, <=1:10.2.1+ds-1
Remediation
Event History
Jun 2, 2021
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Feb 20, 2026
Data Sourced
via Debian·10:34 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-12067?
CVE-2019-12067 is a vulnerability in QEMU that allows attackers to cause a denial of service by triggering a NULL dereference in the ahci_commit_buf function.
2
Which software is affected by CVE-2019-12067?
QEMU and various versions of Debian, Fedora, Redhat Openstack Platform, and Redhat Enterprise Linux are affected.
3
What is the severity of CVE-2019-12067?
CVE-2019-12067 has a severity score of 6.5, which is considered medium.
4
How can I fix CVE-2019-12067?
Apply the appropriate security patches provided by the affected software vendors.
5
Where can I find more information about CVE-2019-12067?
You can find more information about CVE-2019-12067 in the provided references.