{"schema_version":"1.7.5","id":"CVE-2019-12067","published":"2021-06-02T15:15:07.680Z","modified":"2026-07-08T05:52:50.437556643Z","related":["SUSE-SU-2019:14199-1","SUSE-SU-2019:14201-1","SUSE-SU-2020:0388-1"],"details":"The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qemu/qemu","events":[{"introduced":"c25df57ae8f9fe1c72eee2dab37d76d904ac382e"},{"last_affected":"c1eb2ddf0f8075faddc5f7c3d39feae3e8e9d6b4"}],"database_specific":{"cpe":["cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack_platform:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"},{"introduced":"11.0"},{"last_affected":"11.0"},{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING"}}],"versions":["10.0","11.0","8.0","9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12067.json"}}],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2019-12067"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210727-0001/"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1145642"},{"type":"FIX","url":"https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01358.html"},{"type":"FIX","url":"https://lists.gnu.org/archive/html/qemu-devel/2019-08/msg01487.html"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"30"},{"last_affected":"30"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"cpes":["cpe:2.3:a:redhat:openstack_platform:14.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"14.0"},{"last_affected":"14.0"}],"source":"CPE_STRING","vendor_product":"redhat:openstack_platform"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"}]}