CVE-2015-3247: Red Hat Enterprise Linux

Medium severity, CVSS 6.9. EPSS: 1.1% chance of exploitation in the next 30 days.

Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.

Affected products

  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Spice Project Spice: version 0.12.4 only

Published 2015-09-08. Last modified 2026-06-17.