Hide Forgot
It was found that one malicious guest inside a virtual machine can take control of the corresponding Qemu process in the host using crafted primary surface parameters. This issue is similar to CVE-2015-5261, but it's using different path in the code.
Acknowledgments: Name: Frediano Ziglio (Red Hat)
Created spice tracking bugs for this issue: Affects: fedora-all [bug 1343135]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:1205 https://access.redhat.com/errata/RHSA-2016:1205
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:1204 https://access.redhat.com/errata/RHSA-2016:1204