CVE-2015-3247
published 2015-09-08CVE-2015-3247: Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based…
PriorityP429medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
1.14%
63.1th percentile
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | spice | < spice 0.12.5-1.2 (bookworm) | spice 0.12.5-1.2 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| spice_project | spice | — | — |
| spice_project | spice | >= 0 < 0.12.5-1.2 | 0.12.5-1.2 |
| spice_project | spice | >= 0 < 0.12.5-1.2 | 0.12.5-1.2 |
| spice_project | spice | >= 0 < 0.12.5-1.2 | 0.12.5-1.2 |
| spice_project | spice | >= 0 < 0.12.5-1.2 | 0.12.5-1.2 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jcpp-w729-jxmc: Race condition in the worker_update_monitors_config function in SPICE 0
ghsa_unreviewed·2022-05-14
CVE-2015-3247 [MEDIUM] CWE-119 GHSA-jcpp-w729-jxmc: Race condition in the worker_update_monitors_config function in SPICE 0
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
OSV
CVE-2015-3247: Race condition in the worker_update_monitors_config function in SPICE 0
osv·2015-09-08·CVSS 6.9
CVE-2015-3247 [MEDIUM] CVE-2015-3247: Race condition in the worker_update_monitors_config function in SPICE 0
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
Ubuntu
Spice vulnerability
vendor_ubuntu·2015-09-08
CVE-2015-3247 Spice vulnerability
Title: Spice vulnerability
Summary: Spice could be made to crash or run programs.
Frediano Ziglio discovered that Spice incorrectly handled monitor configs.
A malicious guest could use this issue to cause a denial of service, or
possibly execute arbitrary code on the host as the user running the QEMU
process. In the default installation, when QEMU is used with libvirt,
attackers would be isolated by the libvirt AppArmor profile.
Instructions: After a standard system update you need to restart all QEMU virtual
machines using Spice to make the necessary changes.
Red Hat
spice: memory corruption in worker_update_monitors_config()
vendor_redhat·2015-09-03·CVSS 6.9
CVE-2015-3247 [MEDIUM] CWE-362 spice: memory corruption in worker_update_monitors_config()
spice: memory corruption in worker_update_monitors_config()
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
A race condition flaw, leading to a heap-based memory corruption, was found in spice's worker_update_monitors_config() function, which runs under the QEMU-KVM context on the host. A user in a guest could leverage this flaw to crash the host QEMU-KVM process or, possibly, execute arbitrary code with the privileges of the host QEMU-KVM process.
Debian
CVE-2015-3247: spice - Race condition in the worker_update_monitors_config function in SPICE 0.12.4 all...
vendor_debian·2015·CVSS 6.9
CVE-2015-3247 [MEDIUM] CVE-2015-3247: spice - Race condition in the worker_update_monitors_config function in SPICE 0.12.4 all...
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.12.5-1.2)
bullseye: resolved (fixed in 0.12.5-1.2)
forky: resolved (fixed in 0.12.5-1.2)
sid: resolved (fixed in 0.12.5-1.2)
trixie: resolved (fixed in 0.12.5-1.2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3247 spice: memory corruption in worker_update_monitors_config() [fedora-all]
bugzilla·2015-09-07·CVSS 6.9
CVE-2015-3247 [MEDIUM] CVE-2015-3247 spice: memory corruption in worker_update_monitors_config() [fedora-all]
CVE-2015-3247 spice: memory corruption in worker_update_monitors_config() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2015-3247 spice: memory corruption in worker_update_monitors_config()
bugzilla·2015-06-18·CVSS 6.9
CVE-2015-3247 [MEDIUM] CVE-2015-3247 spice: memory corruption in worker_update_monitors_config()
CVE-2015-3247 spice: memory corruption in worker_update_monitors_config()
It was reported that function worker_update_monitors_config in spice-server contains a race condition which can be exploited as a heap corruption from the guest.
Suggested patch: https://bugzilla.redhat.com/attachment.cgi?id=1037193
Acknowledgements:
This issue was discovered by Frediano Ziglio of Red Hat.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2015:1715 https://rhn.redhat.com/errata/RHSA-2015-1715.html
---
This issue has been addressed in the following products:
RHEV-H and Agents for RHEL-6
RHEV-H and Agents for RHEL-7
Via RHSA-2015:1713 https://rhn.redhat.com/errata/RHSA-2015-1713.html
---
This issue has been addressed in the following
http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1713.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1714.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1715.htmlhttp://www.debian.org/security/2015/dsa-3354http://www.securitytracker.com/id/1033459http://www.securitytracker.com/id/1033460http://www.securitytracker.com/id/1033753http://www.ubuntu.com/usn/USN-2736-1http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1713.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1714.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1715.htmlhttp://www.debian.org/security/2015/dsa-3354http://www.securitytracker.com/id/1033459http://www.securitytracker.com/id/1033460http://www.securitytracker.com/id/1033753http://www.ubuntu.com/usn/USN-2736-1
2015-09-08
Published