
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability (CVE-2020-25652) was discovered in the spice-vdagentd daemon, affecting versions 0.20 and prior. The flaw exists in the daemon's handling of client connections via the UNIX domain socket in /run/spice-vdagentd/spice-vdagent-sock. The vulnerability was discovered in September 2020 and publicly disclosed in November 2020 (Openwall).
The vulnerability stems from the daemon's failure to properly handle client connections that can be established via the UNIX domain socket. The daemon does not apply a limit to the amount of client connections, and existing connections aren't subject to a timeout or any preconditions for them to stay alive. The issue has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
Any unprivileged local guest user could exploit this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon, resulting in a denial of service. The highest threat from this vulnerability is to system availability, as attackers could exhaust file descriptors in the daemon, making it unable to accept new connections or perform other tasks (Openwall).
The vulnerability can be exploited by any local user with access to the /run/spice-vdagentd/spice-vdagent-sock socket path. An attacker can open approximately 1020 connections to spice-vdagentd and keep them open without transmitting any data, effectively exhausting the file descriptor limit (Openwall).
The vulnerability was addressed in spice-vdagent version 0.21.0. The fix implements an upper limit of client connections accepted by the spice-vdagentd and a limit for client connections established from the same session. Various Linux distributions have released security updates to address this vulnerability, including Debian, Fedora, and Ubuntu (Debian LTS, Fedora).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."