Descriptionlibspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
spice (PTS)stretch0.12.8-2.1+deb9u3fixed
stretch (security)0.12.8-2.1+deb9u4fixed
buster, buster (security)0.14.0-1.3+deb10u1fixed
bullseye, sid0.14.3-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
spicesource(unstable)(not affected)


- spice <not-affected> (Fixed before initial upload to archive)

Search for package or bug name: Reporting problems