CVE-2020-25652
NixOS vulnerability analysis and mitigation

Overview

A security vulnerability (CVE-2020-25652) was discovered in the spice-vdagentd daemon, affecting versions 0.20 and prior. The flaw exists in the daemon's handling of client connections via the UNIX domain socket in /run/spice-vdagentd/spice-vdagent-sock. The vulnerability was discovered in September 2020 and publicly disclosed in November 2020 (Openwall).

Technical details

The vulnerability stems from the daemon's failure to properly handle client connections that can be established via the UNIX domain socket. The daemon does not apply a limit to the amount of client connections, and existing connections aren't subject to a timeout or any preconditions for them to stay alive. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

Any unprivileged local guest user could exploit this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon, resulting in a denial of service. The highest threat from this vulnerability is to system availability, as attackers could exhaust file descriptors in the daemon, making it unable to accept new connections or perform other tasks (Openwall).

Exploitability

The vulnerability can be exploited by any local user with access to the /run/spice-vdagentd/spice-vdagent-sock socket path. An attacker can open approximately 1020 connections to spice-vdagentd and keep them open without transmitting any data, effectively exhausting the file descriptor limit (Openwall).

Mitigation and workarounds

The vulnerability was addressed in spice-vdagent version 0.21.0. The fix implements an upper limit of client connections accepted by the spice-vdagentd and a limit for client connections established from the same session. Various Linux distributions have released security updates to address this vulnerability, including Debian, Fedora, and Ubuntu (Debian LTS, Fedora).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86993MEDIUM5.9
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86996MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86995MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86994MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86085MEDIUM5.1
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management