Where
-Infinity
0

Vendor Risk Score

See how spice project compares to other vendors in security performance

View Risk Score →
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.

1 / 2
Source: MITRE
First published (updated )
Severity
6.6
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

1 / 3
Source: Ubuntu
First published (updated )
Severity
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An off-by-one error was found in spice when accessing arrays. A malicious guest user can use this for a host denial of service.

1 / 3
Source: Red Hat
First published (updated )
Severity
8.8
Integer Overflow, Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in spice-client. An improper check on LZ images sent by the server could lead to an integer/buffer overflows on the client.

References: https://bugzilla.redhat.com/showbug.cgi?id=1594904

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Buffer Overflow, Input Validation
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

1 / 3
Source: Launchpad
First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

For authenticated client it is possible to cause buffer overflow via sending invalid monitor configurations.

Proposed patch:

https://bugzilla.redhat.com/attachment.cgi?id=1279035

Product bug:

https://bugzilla.redhat.com/showbug.cgi?id=1451021

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Buffer Overflow, Input Validation
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A buffer overflow vulnerability in mainchannelallocmsgrcvbuf was found that occurs when reading large messages due to missing buffer size check.

Product bug:

https://bugzilla.redhat.com/showbug.cgi?id=1401038

1 / 2
Source: Red Hat
First published (updated )
Severity
7.5
Input Validation
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability due to improper incoming messages validation was found in spice server that leads to remote VM crash via crafted message by unauthenticated attacker.

Product bug:

https://bugzilla.redhat.com/showbug.cgi?id=1399161

1 / 2
Source: Red Hat
First published (updated )
Severity
10
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.

First published (updated )
Severity
7.1
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

It was found that one malicious guest inside a virtual machine can take control of the corresponding Qemu process in the host using crafted primary surface parameters. This issue is similar to CVE-2015-5261, but it's using different path in the code.

1 / 2
Source: Red Hat
First published (updated )
Severity
7.1
Buffer Overflow
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

1 / 2
Source: MITRE
First published (updated )
Severity
6.9
Race Condition, Buffer Overflow
AV:L/AC:M/Au:N/C:C/I:C/A:C

Race condition in the workerupdatemonitorsconfig function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

First published (updated )
Severity
7.8
Buffer Overflow
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surfaceid parameter.

1 / 2
Source: MITRE
First published (updated )
Severity
5
Buffer Overflow
AV:N/AC:L/Au:N/C:N/I:N/A:P

Stack-based buffer overflow in the redshandleticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

Currently, both redchannelpipesaddtype() and redchannelpipesaddemptymsg() use plaing RINGFOREACH() which is not safe versus removals from the ring within the loop body. Yet, when (network) error does occur, the current item could be removed from the ring down the road and the assertion in RINGFOREACH()'s ringnext() could trip, causing the process containing the spice server to abort.

An user able to initiate spice connection to the guest could use this flaw to crash the guest.

Upstream fix: http://cgit.freedesktop.org/spice/spice/commit/?id=53488f0275d6c8a121af49f7ac817d09ce68090d

Acknowledgements:

This issue was discovered by David Gibson of Red Hat.

1 / 2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203