CVE-2026-57965

NameCVE-2026-57965
DescriptionA flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This issue requires the SPICE host to be untrusted or compromised for exploitation.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
spice-vdagent (PTS)bullseye0.20.0-2vulnerable
bookworm0.22.1-3vulnerable
trixie0.22.1-4.1vulnerable
forky, sid0.23.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
spice-vdagentsource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2493581

Search for package or bug name: Reporting problems