CVE-2016-9578: Debian Linux

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only
  • Red Hat Enterprise Linux Server Eus: version 7.3 only; version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Spice Project Spice: before 0.13.90 (fixed in 0.13.90)

Published 2018-07-27. Last modified 2026-06-17.