Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Debian LTS DLA-4698-1 Spice-Vdagent Critical DoS Path Traversal

debian lts
Calendar Grey July 24, 2026
Scroller Debian Lts
Upgrade spice-vdagent to fix critical security issues including DoS and path traversal vulnerabilities in Debian.
Debian issued an advisory for spice-vdagent, addressing two vulnerabilities: an integer overflow leading to DoS and a path traversal allowing unauthorized file writes

Summary

CVE-2026-57965

A malicious or compromised SPICE host can trigger an integer
overflow by sending a specially crafted message. This
vulnerability can lead to a heap buffer overflow, causing the
spice-vdagent daemon to crash and resulting in a Denial of Service
(DoS) for the virtual machine.

CVE-2026-57966

A path traversal vulnerability was found in spice-vdagent. This
flaw allows a malicious or compromised SPICE host to write
arbitrary files to any location on the guest operating
system. This occurs because the filename provided by the SPICE
host during file transfers is not properly sanitized before being
used. An attacker could exploit this to write to sensitive
locations with the privileges of the spice-vdagent process,
typically the logged-in user.

For Debian 11 bullseye, these problems have been fixed in version
0.20.0-2+deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
0.22.1-3+deb12u1.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: spice-vdagent
Version: 0.20.0-2+deb11u1 0.22.1-3+deb12u1
CVE ID: CVE-2026-57965 CVE-2026-57966
Debian Bug: 1141317 1141318

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.