UBUNTU-CVE-2019-12928

Source
https://ubuntu.com/security/CVE-2019-12928
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-12928.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-12928
Upstream
Published
2019-06-24T11:15:00Z
Modified
2025-09-08T16:45:27Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote attacker to achieve code execution, denial of service, or information disclosure by sending a crafted QMP command to the listening server. Note: This has been disputed as a non-issue since QEMU's -qmp interface is meant to be used by trusted users. If one is able to access this interface via a tcp socket open to the internet, then it is an insecure configuration issue

References

Affected packages

Ubuntu:Pro:14.04:LTS / qemu

Package

Name
qemu
Purl
pkg:deb/ubuntu/qemu@2.0.0+dfsg-2ubuntu1.47+esm4?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.5.0+dfsg-3ubuntu5
1.5.0+dfsg-3ubuntu6
1.6.0+dfsg-2ubuntu1
1.6.0+dfsg-2ubuntu2
1.6.0+dfsg-2ubuntu3
1.6.0+dfsg-2ubuntu4
1.7.0+dfsg-2ubuntu1
1.7.0+dfsg-2ubuntu2
1.7.0+dfsg-2ubuntu3
1.7.0+dfsg-2ubuntu4
1.7.0+dfsg-2ubuntu5
1.7.0+dfsg-2ubuntu7
1.7.0+dfsg-2ubuntu8
1.7.0+dfsg-2ubuntu9
1.7.0+dfsg-3ubuntu1~ppa1
1.7.0+dfsg-3ubuntu1
1.7.0+dfsg-3ubuntu2
1.7.0+dfsg-3ubuntu3
1.7.0+dfsg-3ubuntu4
1.7.0+dfsg-3ubuntu5
1.7.0+dfsg-3ubuntu6
1.7.0+dfsg-3ubuntu7
2.*
2.0.0~rc1+dfsg-0ubuntu1
2.0.0~rc1+dfsg-0ubuntu2
2.0.0~rc1+dfsg-0ubuntu3
2.0.0~rc1+dfsg-0ubuntu3.1
2.0.0+dfsg-2ubuntu1
2.0.0+dfsg-2ubuntu1.1
2.0.0+dfsg-2ubuntu1.2
2.0.0+dfsg-2ubuntu1.3
2.0.0+dfsg-2ubuntu1.5
2.0.0+dfsg-2ubuntu1.6
2.0.0+dfsg-2ubuntu1.7
2.0.0+dfsg-2ubuntu1.8
2.0.0+dfsg-2ubuntu1.9
2.0.0+dfsg-2ubuntu1.10
2.0.0+dfsg-2ubuntu1.11
2.0.0+dfsg-2ubuntu1.13
2.0.0+dfsg-2ubuntu1.14
2.0.0+dfsg-2ubuntu1.15
2.0.0+dfsg-2ubuntu1.16
2.0.0+dfsg-2ubuntu1.17
2.0.0+dfsg-2ubuntu1.18
2.0.0+dfsg-2ubuntu1.19
2.0.0+dfsg-2ubuntu1.20
2.0.0+dfsg-2ubuntu1.21
2.0.0+dfsg-2ubuntu1.22
2.0.0+dfsg-2ubuntu1.24
2.0.0+dfsg-2ubuntu1.25
2.0.0+dfsg-2ubuntu1.26
2.0.0+dfsg-2ubuntu1.27
2.0.0+dfsg-2ubuntu1.28
2.0.0+dfsg-2ubuntu1.29
2.0.0+dfsg-2ubuntu1.30
2.0.0+dfsg-2ubuntu1.31
2.0.0+dfsg-2ubuntu1.32
2.0.0+dfsg-2ubuntu1.33
2.0.0+dfsg-2ubuntu1.34
2.0.0+dfsg-2ubuntu1.35
2.0.0+dfsg-2ubuntu1.36
2.0.0+dfsg-2ubuntu1.38
2.0.0+dfsg-2ubuntu1.39
2.0.0+dfsg-2ubuntu1.40
2.0.0+dfsg-2ubuntu1.41
2.0.0+dfsg-2ubuntu1.42
2.0.0+dfsg-2ubuntu1.43
2.0.0+dfsg-2ubuntu1.44
2.0.0+dfsg-2ubuntu1.45
2.0.0+dfsg-2ubuntu1.46
2.0.0+dfsg-2ubuntu1.47
2.0.0+dfsg-2ubuntu1.47+esm1
2.0.0+dfsg-2ubuntu1.47+esm2
2.0.0+dfsg-2ubuntu1.47+esm3
2.0.0+dfsg-2ubuntu1.47+esm4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-common"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-guest-agent"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-keymaps"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-kvm"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-aarch64"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-arm"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-common"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-mips"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-misc"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-ppc"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-sparc"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-system-x86"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-user"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-user-static"
        },
        {
            "binary_version": "2.0.0+dfsg-2ubuntu1.47+esm4",
            "binary_name": "qemu-utils"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-12928.json"

Ubuntu:Pro:16.04:LTS / qemu

Package

Name
qemu
Purl
pkg:deb/ubuntu/qemu@1:2.5+dfsg-5ubuntu10.51+esm3?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*
1:2.3+dfsg-5ubuntu9
1:2.3+dfsg-5ubuntu10
1:2.4+dfsg-4ubuntu1
1:2.4+dfsg-4ubuntu2
1:2.4+dfsg-4ubuntu3
1:2.4+dfsg-5ubuntu3
1:2.5+dfsg-1ubuntu2
1:2.5+dfsg-1ubuntu3
1:2.5+dfsg-1ubuntu4
1:2.5+dfsg-1ubuntu5
1:2.5+dfsg-5ubuntu1
1:2.5+dfsg-5ubuntu2
1:2.5+dfsg-5ubuntu4
1:2.5+dfsg-5ubuntu6
1:2.5+dfsg-5ubuntu7
1:2.5+dfsg-5ubuntu10
1:2.5+dfsg-5ubuntu10.1
1:2.5+dfsg-5ubuntu10.2
1:2.5+dfsg-5ubuntu10.3
1:2.5+dfsg-5ubuntu10.4
1:2.5+dfsg-5ubuntu10.5
1:2.5+dfsg-5ubuntu10.6
1:2.5+dfsg-5ubuntu10.7
1:2.5+dfsg-5ubuntu10.8
1:2.5+dfsg-5ubuntu10.9
1:2.5+dfsg-5ubuntu10.10
1:2.5+dfsg-5ubuntu10.11
1:2.5+dfsg-5ubuntu10.13
1:2.5+dfsg-5ubuntu10.14
1:2.5+dfsg-5ubuntu10.15
1:2.5+dfsg-5ubuntu10.16
1:2.5+dfsg-5ubuntu10.20
1:2.5+dfsg-5ubuntu10.21
1:2.5+dfsg-5ubuntu10.22
1:2.5+dfsg-5ubuntu10.24
1:2.5+dfsg-5ubuntu10.25
1:2.5+dfsg-5ubuntu10.26
1:2.5+dfsg-5ubuntu10.28
1:2.5+dfsg-5ubuntu10.29
1:2.5+dfsg-5ubuntu10.30
1:2.5+dfsg-5ubuntu10.31
1:2.5+dfsg-5ubuntu10.32
1:2.5+dfsg-5ubuntu10.33
1:2.5+dfsg-5ubuntu10.34
1:2.5+dfsg-5ubuntu10.35
1:2.5+dfsg-5ubuntu10.36
1:2.5+dfsg-5ubuntu10.37
1:2.5+dfsg-5ubuntu10.38
1:2.5+dfsg-5ubuntu10.39
1:2.5+dfsg-5ubuntu10.40
1:2.5+dfsg-5ubuntu10.41
1:2.5+dfsg-5ubuntu10.42
1:2.5+dfsg-5ubuntu10.43
1:2.5+dfsg-5ubuntu10.44
1:2.5+dfsg-5ubuntu10.45
1:2.5+dfsg-5ubuntu10.46
1:2.5+dfsg-5ubuntu10.47
1:2.5+dfsg-5ubuntu10.48
1:2.5+dfsg-5ubuntu10.49
1:2.5+dfsg-5ubuntu10.51
1:2.5+dfsg-5ubuntu10.51+esm1
1:2.5+dfsg-5ubuntu10.51+esm2
1:2.5+dfsg-5ubuntu10.51+esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-block-extra"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-guest-agent"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-kvm"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-aarch64"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-arm"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-common"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-mips"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-misc"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-ppc"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-s390x"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-sparc"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-system-x86"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-user"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-user-binfmt"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-user-static"
        },
        {
            "binary_version": "1:2.5+dfsg-5ubuntu10.51+esm3",
            "binary_name": "qemu-utils"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-12928.json"

Ubuntu:Pro:18.04:LTS / qemu

Package

Name
qemu
Purl
pkg:deb/ubuntu/qemu@1:2.11+dfsg-1ubuntu7.42+esm2?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:2.*
1:2.10+dfsg-0ubuntu3
1:2.10+dfsg-0ubuntu4
1:2.10+dfsg-0ubuntu5
1:2.11+dfsg-1ubuntu1
1:2.11+dfsg-1ubuntu2
1:2.11+dfsg-1ubuntu4
1:2.11+dfsg-1ubuntu5
1:2.11+dfsg-1ubuntu6
1:2.11+dfsg-1ubuntu7
1:2.11+dfsg-1ubuntu7.1
1:2.11+dfsg-1ubuntu7.2
1:2.11+dfsg-1ubuntu7.3
1:2.11+dfsg-1ubuntu7.4
1:2.11+dfsg-1ubuntu7.5
1:2.11+dfsg-1ubuntu7.6
1:2.11+dfsg-1ubuntu7.7
1:2.11+dfsg-1ubuntu7.8
1:2.11+dfsg-1ubuntu7.9
1:2.11+dfsg-1ubuntu7.10
1:2.11+dfsg-1ubuntu7.12
1:2.11+dfsg-1ubuntu7.13
1:2.11+dfsg-1ubuntu7.14
1:2.11+dfsg-1ubuntu7.15
1:2.11+dfsg-1ubuntu7.17
1:2.11+dfsg-1ubuntu7.18
1:2.11+dfsg-1ubuntu7.19
1:2.11+dfsg-1ubuntu7.20
1:2.11+dfsg-1ubuntu7.21
1:2.11+dfsg-1ubuntu7.22
1:2.11+dfsg-1ubuntu7.23
1:2.11+dfsg-1ubuntu7.25
1:2.11+dfsg-1ubuntu7.26
1:2.11+dfsg-1ubuntu7.27
1:2.11+dfsg-1ubuntu7.28
1:2.11+dfsg-1ubuntu7.29
1:2.11+dfsg-1ubuntu7.31
1:2.11+dfsg-1ubuntu7.32
1:2.11+dfsg-1ubuntu7.33
1:2.11+dfsg-1ubuntu7.34
1:2.11+dfsg-1ubuntu7.35
1:2.11+dfsg-1ubuntu7.36
1:2.11+dfsg-1ubuntu7.37
1:2.11+dfsg-1ubuntu7.38
1:2.11+dfsg-1ubuntu7.39
1:2.11+dfsg-1ubuntu7.40
1:2.11+dfsg-1ubuntu7.41
1:2.11+dfsg-1ubuntu7.42
1:2.11+dfsg-1ubuntu7.42+esm1
1:2.11+dfsg-1ubuntu7.42+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-block-extra"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-guest-agent"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-kvm"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-arm"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-common"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-mips"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-misc"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-ppc"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-s390x"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-sparc"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-system-x86"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-user"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-user-binfmt"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-user-static"
        },
        {
            "binary_version": "1:2.11+dfsg-1ubuntu7.42+esm2",
            "binary_name": "qemu-utils"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-12928.json"