CVE-2019-12155: Qemu

High severity, CVSS 7.5. EPSS: 5.5% chance of exploitation in the next 30 days.

interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.

Affected products

  • Qemu Qemu: version 4.0.0 only

Published 2019-05-24. Last modified 2026-06-17.