CVE-2016-2150

Related Vulnerabilities: CVE-2016-2150  

A memory access flaw was found in the way spice handled certain guests using crafted primary surface parameters. A user in a guest could use this flaw to read from and write to arbitrary memory locations on the host.

A memory access flaw was found in the way spice handled certain guests using crafted primary surface parameters. A user in a guest could use this flaw to read from and write to arbitrary memory locations on the host.

Find out more about CVE-2016-2150 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:A/AC:M/Au:N/C:P/I:N/A:P
Access Vector Adjacent Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (spice-server) RHSA-2016:1204 2016-06-06
Red Hat Enterprise Linux 7 (spice) RHSA-2016:1205 2016-06-06

Acknowledgements

This issue was discovered by Frediano Ziglio (Red Hat).