These patches were worked internally in RedHat and CVE was published on June 6th 2016. See https://access.redhat.com/security/cve/cve-2016-2150. Frediano Ziglio (2): factor out red_validate_surface function to validate surface parameters improve primary surface parameter checks server/red-parse-qxl.c | 49 ++++++++++++++++++++++++++++++++----------------- server/red-parse-qxl.h | 3 +++ server/red-worker.c | 11 +++++++++-- 3 files changed, 44 insertions(+), 19 deletions(-) -- 2.7.4 _______________________________________________ Spice-devel mailing list Spice-devel@xxxxxxxxxxxxxxxxxxxxx https://lists.freedesktop.org/mailman/listinfo/spice-devel