CVE-2019-12068

Priority
Description
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8,
1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12
(fixed), when executing script in lsi_execute_script(), the LSI scsi
adapter emulator advances 's->dsp' index to read next opcode. This can lead
to an infinite loop if the next opcode is empty. Move the existing loop
exit after 10k iterations so that it covers no-op opcodes as well.
Ubuntu-Description
It was discovered that the LSI SCSI adapter emulator implementation in
QEMU did not properly validate executed scripts. A local attacker could
use this to cause a denial of service.
Assigned-to
sbeattie
Notes
Package
Source: qemu (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):released (2.0.0+dfsg-2ubuntu1.47)
Ubuntu 16.04 LTS (Xenial Xerus):released (1:2.5+dfsg-5ubuntu10.42)
Ubuntu 18.04 LTS (Bionic Beaver):released (1:2.11+dfsg-1ubuntu7.20)
Ubuntu 19.04 (Disco Dingo):released (1:3.1+dfsg-2ubuntu3.6)
Ubuntu 19.10 (Eoan Ermine):released (1:4.0+dfsg-0ubuntu9.1)
Ubuntu 20.04 (Focal Fossa):needed
Patches:
Upstream:https://git.qemu.org/?p=qemu.git;a=commit;h=de594e47659029316bbf9391efb79da0a1a08e08
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):needed
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 19.04 (Disco Dingo):DNE
Ubuntu 19.10 (Eoan Ermine):DNE
Ubuntu 20.04 (Focal Fossa):DNE
More Information

Updated: 2019-12-05 19:59:12 UTC (commit 0aa5e7c87c8b55d2ec5c7f4ca1179cf75de91961)