CVE-2015-5260
published 2016-06-07CVE-2015-5260: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or…
PriorityP336high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.57%
43.6th percentile
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | spice | < spice 0.12.5-1.3 (bookworm) | spice 0.12.5-1.3 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| spice_project | spice | <= 0.12.5 | — |
| spice_project | spice | >= 0 < 0.12.5-1.3 | 0.12.5-1.3 |
| spice_project | spice | >= 0 < 0.12.5-1.3 | 0.12.5-1.3 |
| spice_project | spice | >= 0 < 0.12.5-1.3 | 0.12.5-1.3 |
| spice_project | spice | >= 0 < 0.12.5-1.3 | 0.12.5-1.3 |
| spice_project | spice | >= 0 < 0.12.4-0nocelt2ubuntu1.2 | 0.12.4-0nocelt2ubuntu1.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spice vulnerabilities
vendor_ubuntu·2015-10-07·CVSS 7.8
CVE-2015-5260 [HIGH] Spice vulnerabilities
Title: Spice vulnerabilities
Summary: Spice could be made to crash or run programs.
Frediano Ziglio discovered multiple buffer overflows, undefined behavior
signed integer operations, race conditions, memory leaks, and denial
of service issues in Spice. A malicious guest operating system could
potentially exploit these issues to escape virtualization. (CVE-2015-5260,
CVE-2015-5261)
Instructions: After a standard system update you need to restart qemu guests to make
all the necessary changes.
Red Hat
spice: insufficient validation of surface_id parameter can cause crash
vendor_redhat·2015-09-08·CVSS 7.8
CVE-2015-5260 [HIGH] CWE-20 spice: insufficient validation of surface_id parameter can cause crash
spice: insufficient validation of surface_id parameter can cause crash
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
A heap-based buffer overflow flaw was found in the way spice handled certain QXL commands related to the "surface_id" parameter. A user in a guest could use this flaw to crash the host QEMU-KVM process or, possibly, execute arbitrary code with the privileges of the host QEMU-KVM process.
Debian
CVE-2015-5260: spice - Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause...
vendor_debian·2015·CVSS 7.8
CVE-2015-5260 [HIGH] CVE-2015-5260: spice - Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause...
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
Scope: local
bookworm: resolved (fixed in 0.12.5-1.3)
bullseye: resolved (fixed in 0.12.5-1.3)
forky: resolved (fixed in 0.12.5-1.3)
sid: resolved (fixed in 0.12.5-1.3)
trixie: resolved (fixed in 0.12.5-1.3)
GHSA
GHSA-3ggj-v8pg-xq6f: Heap-based buffer overflow in SPICE before 0
ghsa_unreviewed·2022-05-17
CVE-2015-5260 [HIGH] CWE-119 GHSA-3ggj-v8pg-xq6f: Heap-based buffer overflow in SPICE before 0
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
OSV
CVE-2015-5260: Heap-based buffer overflow in SPICE before 0
osv·2016-06-07·CVSS 7.8
CVE-2015-5260 [HIGH] CVE-2015-5260: Heap-based buffer overflow in SPICE before 0
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
OSV
spice vulnerabilities
osv·2015-10-07·CVSS 7.8
CVE-2015-5260 [HIGH] spice vulnerabilities
spice vulnerabilities
Frediano Ziglio discovered multiple buffer overflows, undefined behavior
signed integer operations, race conditions, memory leaks, and denial
of service issues in Spice. A malicious guest operating system could
potentially exploit these issues to escape virtualization. (CVE-2015-5260,
CVE-2015-5261)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5260 spice: insufficient validation of surface_id parameter can cause crash [fedora-all]
bugzilla·2015-09-08·CVSS 7.8
CVE-2015-5260 [HIGH] CVE-2015-5260 spice: insufficient validation of surface_id parameter can cause crash [fedora-all]
CVE-2015-5260 spice: insufficient validation of surface_id parameter can cause crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2015-5260 spice: insufficient validation of surface_id parameter can cause crash
bugzilla·2015-09-08·CVSS 7.8
CVE-2015-5260 [HIGH] CVE-2015-5260 spice: insufficient validation of surface_id parameter can cause crash
CVE-2015-5260 spice: insufficient validation of surface_id parameter can cause crash
surface_id is a field for many QXL commands (commands that a guest can freely craft and send). Particularly are used to create and destroy new surfaces. This field is used as an index for a static allocated array.
In different paths, the value passes without being stopped (in many cases it just give some warnings if enabled) so you can corrupt memory very easily.
A client can be modified to produce memory corruption. Although it is not easy to write specific data at a specific offset, it is still possible to write some value at some offset (dirtying near data). This means that the problem can be used for heap corruption which is usually exploitable.
Discussion:
Created spice tracking bugs for this issue
http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1889.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1890.htmlhttp://www.debian.org/security/2015/dsa-3371http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77019http://www.securitytracker.com/id/1033753http://www.ubuntu.com/usn/USN-2766-1https://bugzilla.redhat.com/show_bug.cgi?id=1260822https://security.gentoo.org/glsa/201606-05http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1889.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1890.htmlhttp://www.debian.org/security/2015/dsa-3371http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/77019http://www.securitytracker.com/id/1033753http://www.ubuntu.com/usn/USN-2766-1https://bugzilla.redhat.com/show_bug.cgi?id=1260822https://security.gentoo.org/glsa/201606-05
2016-06-07
Published