ISOMAN

CVE

CVE-2019-12068

In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.

Severity
LOW
CVSS
3.8
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html
  3. https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=de594e47659029316bbf9391efb79da0a1a08e08
  4. https://lists.debian.org/debian-lts-announce/2019/09/msg00021.html
  5. https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html
  6. https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.html
  7. https://security-tracker.debian.org/tracker/CVE-2019-12068
  8. https://usn.ubuntu.com/4191-1/
  9. https://usn.ubuntu.com/4191-2/
  10. https://www.debian.org/security/2020/dsa-4665
  11. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html
  12. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00038.html
  13. https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=de594e47659029316bbf9391efb79da0a1a08e08
  14. https://lists.debian.org/debian-lts-announce/2019/09/msg00021.html
  15. https://lists.debian.org/debian-lts-announce/2020/07/msg00020.html
  16. https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01518.html
  17. https://security-tracker.debian.org/tracker/CVE-2019-12068
  18. https://usn.ubuntu.com/4191-1/
  19. https://usn.ubuntu.com/4191-2/
  20. https://www.debian.org/security/2020/dsa-4665