It was reported that function worker_update_monitors_config in spice-server contains a race condition which can be exploited as a heap corruption from the guest. Suggested patch: https://bugzilla.redhat.com/attachment.cgi?id=1037193 Acknowledgements: This issue was discovered by Frediano Ziglio of Red Hat.
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2015:1715 https://rhn.redhat.com/errata/RHSA-2015-1715.html
This issue has been addressed in the following products: RHEV-H and Agents for RHEL-6 RHEV-H and Agents for RHEL-7 Via RHSA-2015:1713 https://rhn.redhat.com/errata/RHSA-2015-1713.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:1714 https://rhn.redhat.com/errata/RHSA-2015-1714.html
Created spice tracking bugs for this issue: Affects: fedora-all [bug 1260598]
*** Bug 1230118 has been marked as a duplicate of this bug. ***