Executive brief
A security flaw was found in spice-vdagent, a tool used to improve the user experience in virtual machines by enabling features like file transfers. A compromised or malicious host machine can exploit this to write files to any location on the virtual guest system. This could allow an attacker to overwrite sensitive user data or system configuration files, potentially leading to a full compromise of the virtual machine.
Technical details
A path traversal vulnerability (CWE-22) exists in spice-vdagent within the file transfer handling logic in 'src/vdagent/file-xfers.c'. The component fails to sanitize filenames provided by the SPICE host before passing them to 'g_build_filename()'. Because 'g_build_filename()' discards the base directory if the provided filename is an absolute path, or allows '..' components, a malicious host can bypass the intended save directory. An attacker with control over the SPICE host can write arbitrary files to the guest filesystem with the privileges of the 'spice-vdagent' process, which typically runs as the logged-in user. This vulnerability is distinct from previous command injection issues in the same component.
Affected products
- Red Hat Red Hat Enterprise Linux 10 All versions
- Red Hat Red Hat Enterprise Linux 6 All versions
- Red Hat Red Hat Enterprise Linux 7 All versions
- Red Hat Red Hat Enterprise Linux 8 All versions
- Red Hat Red Hat Enterprise Linux 9 All versions
- SPICE Project spice-vdagent All versions
Timeline
- 2026-06-26: disclosed: Initial report in Red Hat Bugzilla
- 2026-06-29: advisory: NVD publication date