Oval Definition:oval:com.ubuntu.bionic:def:2019120680000000
Revision Date:2019-09-24Version:1
Title:CVE-2019-12068 on Ubuntu 18.04 LTS (bionic) - low.
Description:In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well. It was discovered that the LSI SCSI adapter emulator implementation in QEMU did not properly validate executed scripts. A local attacker could use this to cause a denial of service.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-12068
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND qemu package in bionic was vulnerable but has been fixed (note: '1:2.11+dfsg-1ubuntu7.20').
  • BACK