CVE-2019-12067 PUBLISHED

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

EPSS 0.16% · 37.3th percentile

Risk Scores

EPSS Score
0.16%
37.3th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSqemu1:6.2+dfsg-2ubuntu6.27, 1:6.2+dfsg-2ubuntu6.26, 1:6.2+dfsg-2ubuntu6.25
Ubuntu:Pro:14.04:LTSqemu2.0.0+dfsg-2ubuntu1.6, 2.0.0+dfsg-2ubuntu1.7, 2.0.0+dfsg-2ubuntu1.8
Ubuntu:20.04:LTSqemu1:4.2-3ubuntu6.18, 0, 1:4.0+dfsg-0ubuntu9
Ubuntu:25.10qemu1:10.1.0+ds-5ubuntu2.1, 1:10.1.0+ds-5ubuntu1, 1:10.1.0+ds-5ubuntu2.2
Ubuntu:24.04:LTSqemu1:8.0.4+dfsg-1ubuntu3, 1:8.0.4+dfsg-1ubuntu5, 1:8.2.2+ds-0ubuntu1.6
Ubuntu:Pro:18.04:LTSqemu1:2.11+dfsg-1ubuntu7.39, 1:2.11+dfsg-1ubuntu7.40, 1:2.11+dfsg-1ubuntu7.41
Ubuntu:Pro:16.04:LTSqemu1:2.5+dfsg-5ubuntu10.42, 1:2.5+dfsg-1ubuntu3, 1:2.5+dfsg-1ubuntu2

Timeline

References

Open in Interactive Console →