CVE-2019-12068: Low severity Qemu Qemu vulnerability
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsiexecutescript(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12068?
The severity of CVE-2019-12068 is low.
How does CVE-2019-12068 affect QEMU?
CVE-2019-12068 affects QEMU versions 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed).
How can I fix CVE-2019-12068 in QEMU?
To fix CVE-2019-12068 in QEMU, update to version 1:4.1-2 or later.
Is Debian Linux affected by CVE-2019-12068?
Debian Linux versions 8.0, 9.0, and 10.0 are not vulnerable to CVE-2019-12068.
Where can I find more information about CVE-2019-12068?
More information about CVE-2019-12068 can be found at the following references: - [GIT Commit](https://git.qemu.org/?p=qemu.git;a=commit;h=de594e47659029316bbf9391efb79da0a1a08e08) - [QEMU Development Mailing List](https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.html) - [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2019-12068)