CVE-2015-5261
published 2016-06-07CVE-2015-5261: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands…
PriorityP336high7.1CVSS 3.0
AVLACLPRLUINSUCHIHAN
EPSS
0.49%
38.7th percentile
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | spice | < spice 0.12.5-1.3 (bookworm) | spice 0.12.5-1.3 (bookworm) |
| debian | spice | < spice 0.12.6-4.1 (bookworm) | spice 0.12.6-4.1 (bookworm) |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| spice_project | spice | <= 0.12.5 | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w69p-8vxh-m87g: Heap-based buffer overflow in SPICE before 0
ghsa_unreviewed·2022-05-17
CVE-2015-5261 [HIGH] CWE-119 GHSA-w69p-8vxh-m87g: Heap-based buffer overflow in SPICE before 0
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
GHSA
GHSA-xcwp-848r-pq94: SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to
ghsa_unreviewed·2022-05-14·CVSS 7.1
CVE-2016-2150 [HIGH] CWE-284 GHSA-xcwp-848r-pq94: SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
OSV
CVE-2016-2150: SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to
osv·2016-06-09·CVSS 7.1
CVE-2016-2150 [HIGH] CVE-2016-2150: SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
OSV
CVE-2015-5261: Heap-based buffer overflow in SPICE before 0
osv·2016-06-07·CVSS 7.1
CVE-2015-5261 [HIGH] CVE-2015-5261: Heap-based buffer overflow in SPICE before 0
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
OSV
spice vulnerabilities
osv·2015-10-07·CVSS 7.8
CVE-2015-5260 [HIGH] spice vulnerabilities
spice vulnerabilities
Frediano Ziglio discovered multiple buffer overflows, undefined behavior
signed integer operations, race conditions, memory leaks, and denial
of service issues in Spice. A malicious guest operating system could
potentially exploit these issues to escape virtualization. (CVE-2015-5260,
CVE-2015-5261)
Red Hat
spice: Host memory access from guest with invalid primary surface parameters
vendor_redhat·2016-06-06·CVSS 7.1
CVE-2016-2150 [HIGH] spice: Host memory access from guest with invalid primary surface parameters
spice: Host memory access from guest with invalid primary surface parameters
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
A memory access flaw was found in the way spice handled certain guests using crafted primary surface parameters. A user in a guest could use this flaw to read from and write to arbitrary memory locations on the host.
Debian
CVE-2016-2150: spice - SPICE allows local guest OS users to read from or write to arbitrary host memory...
vendor_debian·2016·CVSS 7.1
CVE-2016-2150 [HIGH] CVE-2016-2150: spice - SPICE allows local guest OS users to read from or write to arbitrary host memory...
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
Scope: local
bookworm: resolved (fixed in 0.12.6-4.1)
bullseye: resolved (fixed in 0.12.6-4.1)
forky: resolved (fixed in 0.12.6-4.1)
sid: resolved (fixed in 0.12.6-4.1)
trixie: resolved (fixed in 0.12.6-4.1)
Ubuntu
Spice vulnerabilities
vendor_ubuntu·2015-10-07·CVSS 7.8
CVE-2015-5260 [HIGH] Spice vulnerabilities
Title: Spice vulnerabilities
Summary: Spice could be made to crash or run programs.
Frediano Ziglio discovered multiple buffer overflows, undefined behavior
signed integer operations, race conditions, memory leaks, and denial
of service issues in Spice. A malicious guest operating system could
potentially exploit these issues to escape virtualization. (CVE-2015-5260,
CVE-2015-5261)
Instructions: After a standard system update you need to restart qemu guests to make
all the necessary changes.
Red Hat
spice: host memory access from guest using crafted images
vendor_redhat·2015-10-06·CVSS 7.1
CVE-2015-5261 [HIGH] spice: host memory access from guest using crafted images
spice: host memory access from guest using crafted images
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
A heap-based buffer overflow flaw was found in the way SPICE handled certain guest QXL commands related to surface creation. A user in a guest could use this flaw to read and write arbitrary memory locations on the host.
Debian
CVE-2015-5261: spice - Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read ...
vendor_debian·2015·CVSS 7.1
CVE-2015-5261 [HIGH] CVE-2015-5261: spice - Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read ...
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
Scope: local
bookworm: resolved (fixed in 0.12.5-1.3)
bullseye: resolved (fixed in 0.12.5-1.3)
forky: resolved (fixed in 0.12.5-1.3)
sid: resolved (fixed in 0.12.5-1.3)
trixie: resolved (fixed in 0.12.5-1.3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
bugzilla·2016-03-01·CVSS 7.1
CVE-2016-2150 [HIGH] CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
CVE-2016-2150 spice: Host memory access from guest with invalid primary surface parameters
It was found that one malicious guest inside a virtual machine can take control of the corresponding Qemu process in the host using crafted primary surface parameters. This issue is similar to CVE-2015-5261, but it's using different path in the code.
Discussion:
Acknowledgments:
Name: Frediano Ziglio (Red Hat)
---
Created spice tracking bugs for this issue:
Affects: fedora-all [bug 1343135]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1205 https://access.redhat.com/errata/RHSA-2016:1205
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1204 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2015-5261 spice: host memory access from guest using crafted images
bugzilla·2015-09-10·CVSS 7.1
CVE-2015-5261 [HIGH] CVE-2015-5261 spice: host memory access from guest using crafted images
CVE-2015-5261 spice: host memory access from guest using crafted images
The following flaw was reported in spice:
It is possible for a guest issuing QXL commands to host to allow reading and writing host memory in a range of about 16-20gb.
The guest can create a surface very large (say 1000000 x 1000000). If width * height overflow the 32 bit and became a small number the host will accept the command and will create the surface. Now guest can copy areas of surfaces to access any area of memory covered by the image. Considering overflows, pixman implementation and image formats (32 bit, top-down or down-top) the range (the guest pass an offset into video memory for the start) the range if about +/- 8gb.
Discussion:
Acknowledgements:
This issue was discovered by Frediano Ziglio of Red H
http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1889.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1890.htmlhttp://www.debian.org/security/2015/dsa-3371http://www.openwall.com/lists/oss-security/2015/10/06/4http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securitytracker.com/id/1033753http://www.ubuntu.com/usn/USN-2766-1https://bugzilla.redhat.com/show_bug.cgi?id=1261889https://security.gentoo.org/glsa/201606-05http://lists.freedesktop.org/archives/spice-devel/2015-October/022191.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1889.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1890.htmlhttp://www.debian.org/security/2015/dsa-3371http://www.openwall.com/lists/oss-security/2015/10/06/4http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securitytracker.com/id/1033753http://www.ubuntu.com/usn/USN-2766-1https://bugzilla.redhat.com/show_bug.cgi?id=1261889https://security.gentoo.org/glsa/201606-05
2016-06-07
Published