CVE-2020-25651: Infoleak
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.
Other sources
A flaw was found in the SPICE file transfer protocol. It was reported by SUSE Security as follows:
The host application (tested with remote-viewer from the virt-viewer package) chooses an incrementally growing taskid for file exchanges which starts counting at 1. Thus the taskid is predictable. Since any unauthenticated local client can replace the mapping of taskid to client connection by its own client connection, there is a possibility for an attacker to obtain parts of the transferred file data.
File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Exploitability will be difficult if there is not a suitable side channel with information about file transfers going on. In any case active file transfers from other users can also be interrupted (DoS aspect).
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-25651?
CVE-2020-25651 is a vulnerability found in the SPICE file transfer protocol that allows an illegitimate local user in the VM system to access file data from the host system and interrupt active file transfers, resulting in a denial of service.
What is the severity of CVE-2020-25651?
The severity of CVE-2020-25651 is medium with a CVSS score of 6.4.
Which software and versions are affected by CVE-2020-25651?
The affected software includes Spice-vdagent version up to 0.20.0, Debian Linux version 9.0, Fedora 32, and Fedora 33.
How can CVE-2020-25651 be fixed?
To fix CVE-2020-25651, update Spice-vdagent to version 0.21.0.
Where can I find more information about CVE-2020-25651?
You can find more information about CVE-2020-25651 on the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=1886359), [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2021/01/msg00012.html), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GQT56LATVTB2DJOVVJOKQVMVUXYCT2VB/)