CVE-2010-0429: Medium severity qspice vulnerability
Izik Eidus found a bug in QEMU that allows priviledged guest user to force QEMU process on the host to issue free() and/or malloc() calls at addresses controlled by the guest user. The bug is in QXL/libspice code.
Other sources
libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0429?
CVE-2010-0429 is classified as a high severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2010-0429?
To mitigate CVE-2010-0429, you should upgrade to an unaffected version of QEMU and the related libspice components.
Who is affected by CVE-2010-0429?
CVE-2010-0429 affects users running QEMU with the QXL/libspice code on Red Hat Enterprise Virtualization and Qspice 0.3.0.
What are the potential risks associated with CVE-2010-0429?
The risks associated with CVE-2010-0429 include potential privilege escalation and denial of service due to uncontrolled memory management.
When was CVE-2010-0429 reported?
CVE-2010-0429 was reported in early 2010, highlighting a critical vulnerability in virtualized environments.