Security update for spice

SUSE Security Update: Security update for spice
Announcement ID: SUSE-SU-2021:14744-1
Rating: important
References: #1177158 #1181686 #982386
Cross-References:CVE-2016-2150 CVE-2020-14355 CVE-2021-20201
Affected Products:
  • SUSE Linux Enterprise Server 11-SP4-LTSS
  • SUSE Linux Enterprise Debuginfo 11-SP4

An update that fixes three vulnerabilities is now available.


This update for spice fixes the following issues:

  • CVE-2021-20201: client initiated renegotiation causing denial of service (bsc#1181686)
  • CVE-2020-14355: Fixed multiple buffer overflow vulnerabilities in QUIC decoding code (bsc#1177158)
  • CVE-2016-2150: Fixed a guest escape using crafted primary surface parameters (bsc#982386)

Patch Instructions:

To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Server 11-SP4-LTSS:
    zypper in -t patch slessp4-spice-14744=1
  • SUSE Linux Enterprise Debuginfo 11-SP4:
    zypper in -t patch dbgsp4-spice-14744=1

Package List:

  • SUSE Linux Enterprise Server 11-SP4-LTSS (i586 x86_64):
    • libspice-server1-0.12.4-21.1
  • SUSE Linux Enterprise Debuginfo 11-SP4 (i586 x86_64):
    • spice-debuginfo-0.12.4-21.1
    • spice-debugsource-0.12.4-21.1