A vulnerability due to improper incoming messages validation was found in spice server that leads to remote VM crash via crafted message by unauthenticated attacker. Product bug: https://bugzilla.redhat.com/show_bug.cgi?id=1399161
Acknowledgments: Name: Frediano Ziglio (Red Hat)
According to Errata this is no more under Embargo. Before pushing the patches publicly, it this true? Was the errata released?
Hi Christophe, errata are nearly ready for push, so I'm targetting an unembargo date of 2017-02-06 (Monday). If this date works for you, please let me know and I'll arrange notification to other distributions via linux-distros and include copies of the patches against trunk from bug 1401038, bug 1399161. Apologies for the delays and confusion with this - people being away with shutdown, PTO and devconf, and my own mis-handling of the errata, made this take longer than it should have. Thanks for your patience and communication throughout!
Yup, sounds good to me, thanks for the update!
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2017:0254 https://rhn.redhat.com/errata/RHSA-2017-0254.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2017:0253 https://rhn.redhat.com/errata/RHSA-2017-0253.html
This issue has been addressed in the following products: RHEV 4.X RHEV-H and Agents for RHEL-7 Via RHSA-2017:0552 https://access.redhat.com/errata/RHSA-2017:0552
This issue has been addressed in the following products: RHEV 4.X RHEV-H and Agents for RHEL-7 Via RHSA-2017:0549 https://rhn.redhat.com/errata/RHSA-2017-0549.html