Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
CVE-2026-57965
A malicious or compromised SPICE host can trigger an integer
overflow by sending a specially crafted message. This
vulnerability can lead to a heap buffer overflow, causing the
spice-vdagent daemon to crash and resulting in a Denial of Service
(DoS) for the virtual machine.
CVE-2026-57966
A path traversal vulnerability was found in spice-vdagent. This
flaw allows a malicious or compromised SPICE host to write
arbitrary files to any location on the guest operating
system. This occurs because the filename provided by the SPICE
host during file transfers is not properly sanitized before being
used. An attacker could exploit this to write to sensitive
locations with the privileges of the spice-vdagent process,
typically the logged-in user.
For Debian 11 bullseye, these problems have been fixed in version
0.20.0-2+deb11u1.
For Debian 12 bookworm, these problems have been fixed in version
0.22.1-3+deb12u1.
Get the latest Linux and open source security news straight to your inbox.