Wind River Support Network

HomeDefectsLIN1021-6426
Fixed

LIN1021-6426 : Security Advisory - spice - CVE-2020-23793

Created: Aug 28, 2023    Updated: Sep 7, 2023
Resolved Date: Sep 7, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.

CREATE(Triage):(User=admin) CVE-2020-23793 (https://nvd.nist.gov/vuln/detail/CVE-2020-23793)
Live chat
Online