suse · CVE-2015-5261

Quick triage

Priority: high Published: 2021-05-30 13:31:54 UTC Updated: 2025-11-05 04:46:44 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-5261 severity important: SUSE including 39 source package names (libspice-server-devel, libspice-server-devel-0.12.4-5.1, …), 109 product×package rows across 67 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 5, … (67 product lines)): Known Not Affected 57, Fixed 52.

Description:

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

cvelogic Threat Intelligence