Infinite loop in QEMU - CVE-2019-12068
Published: November 14, 2019 / Updated: April 28, 2020
Vulnerability identifier: #VU22783
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12068
CWE-ID: CWE-835
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in lsi_execute_script() when reading empty opcode. A local user can consume all available system resources and cause denial of service conditions.
Affected software
QEMU
qemu (Ubuntu package)
qemu (Debian package)
Opensuse
qemu (Ubuntu package)
qemu (Debian package)
Opensuse
How to mitigate CVE-2019-12068
Install update from vendor's website.
QEMU - update to 4.1.1
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.42, 1:2.11+dfsg-1ubuntu7.20, 1:3.1+dfsg-2ubuntu3.6, 1:4.0+dfsg-0ubuntu9.1
qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u5
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.42, 1:2.11+dfsg-1ubuntu7.20, 1:3.1+dfsg-2ubuntu3.6, 1:4.0+dfsg-0ubuntu9.1
qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u5
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html
- https://git.qemu.org/?p=qemu.git;a=commit;h=de594e47659029316bbf9391efb79da0a1a08e08
- https://lists.debian.org/debian-lts-announce/2019/09/msg00021.html
- https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.html
- https://security-tracker.debian.org/tracker/CVE-2019-12068
- https://usn.ubuntu.com/4191-2/