CVE-2020-14355: Canonical Ubuntu Linux

Medium severity, CVSS 6.6. EPSS: 2.7% chance of exploitation in the next 30 days.

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
  • Debian Debian Linux: version 9.0 only
  • Opensuse Leap: version 15.2 only
  • Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Aus: version 8.2 only
  • Red Hat Enterprise Linux Eus: version 8.1 only
  • Red Hat Enterprise Linux Tus: version 8.2 only
  • Red Hat Enterprise Linux Update Services For SAP Solutions: version 8.0 only
  • Red Hat Openstack: version 16.1 only
  • Spice Project Spice: before 0.14.2 (fixed in 0.14.2)

Published 2020-10-07. Last modified 2026-06-17.