CVE-2019-12068: Canonical Ubuntu Linux
Low severity, CVSS 3.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Qemu Qemu: version 1:4.1-1 only; version 1:2.1+dfsg-12+deb8u6 only; version 1:2.8+dfsg-6+deb9u8 only; version 1:3.1+dfsg-8+deb10u2 only; version 1:3.1+dfsg-8~deb10u1 only
Published 2019-09-24. Last modified 2026-06-17.