Description
A memory allocation flaw, leading to a heap-based buffer overflow, was found
in spice's smartcard interaction, which runs under the QEMU-KVM context on the
host. A user connecting to a guest VM using spice could potentially use this
flaw to crash the QEMU-KVM process or execute arbitrary code with the privileges
of the host's QEMU-KVM process. (CVE-2016-0749)
* A memory access flaw was found in the way spice handled certain guests using
crafted primary surface parameters. A user in a guest could use this flaw to
read from and write to arbitrary memory locations on the host. (CVE-2016-2150)