qemu is vulnerable to denial of service. The vulnerability exists when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full, a malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU.