Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-12067

Опубликовано: 09 окт. 2019
Источник: redhat
CVSS3: 3.2
EPSS Низкий

Описание

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

A NULL pointer dereference flaw was found in the QEMU emulator's IDE AHCI emulator. Exploitation of the flaw could occur while committing DMA buffer in ahci_commit_buf() if the command header 'ad->cur_cmd' was null. A privileged guest user could use this flaw to crash the QEMU process instance resulting in DoS. Reduced performance of the system is the highest threat to the system.

Отчет

The qemu-kvm package versions as shipped with Red Hat Enterprise Linux 6 and 7 are not affected by this issue. The qemu-kvm package version as shipped with Red Hat Enterprise Linux 8 is affected by this issue. Future qemu-kvm updates for Red Hat Enterprise Linux 8 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmNot affected
Red Hat Enterprise Linux 5xenNot affected
Red Hat Enterprise Linux 6qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvmNot affected
Red Hat Enterprise Linux 7qemu-kvm-maNot affected
Red Hat Enterprise Linux 7qemu-kvm-rhevNot affected
Red Hat Enterprise Linux 8qemu-kvmFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationqemu-kvmFix deferred
Red Hat OpenStack Platform 10 (Newton)qemu-kvm-rhevOut of support scope
Red Hat OpenStack Platform 13 (Queens)qemu-kvm-rhevNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1759820QEMU: NULL dereference in ahci_commit_buf() leading to DoS

EPSS

Процентиль: 38%
0.00165
Низкий

3.2 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

CVSS3: 6.5
nvd
больше 4 лет назад

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

CVSS3: 6.5
debian
больше 4 лет назад

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to ...

CVSS3: 6.5
github
больше 3 лет назад

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

CVSS3: 3.3
fstec
больше 6 лет назад

Уязвимость программного обеспечения для эмуляции аппаратного обеспечения различных платформ QEMU, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00165
Низкий

3.2 Low

CVSS3