-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4698-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
July 24, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : spice-vdagent
Version        : 0.20.0-2+deb11u1 0.22.1-3+deb12u1
CVE ID         : CVE-2026-57965 CVE-2026-57966
Debian Bug     : 1141317 1141318

Two vulnerabilities were discovered in spice-vdagent, an agent program
under the SPICE project to ease the remote access to virtual machines
such as clipboard sharing, auto screen resizing. 

CVE-2026-57965

    A malicious or compromised SPICE host can trigger an integer
    overflow by sending a specially crafted message. This
    vulnerability can lead to a heap buffer overflow, causing the
    spice-vdagent daemon to crash and resulting in a Denial of Service
    (DoS) for the virtual machine.

CVE-2026-57966

    A path traversal vulnerability was found in spice-vdagent. This
    flaw allows a malicious or compromised SPICE host to write
    arbitrary files to any location on the guest operating
    system. This occurs because the filename provided by the SPICE
    host during file transfers is not properly sanitized before being
    used. An attacker could exploit this to write to sensitive
    locations with the privileges of the spice-vdagent process,
    typically the logged-in user.

For Debian 11 bullseye, these problems have been fixed in version
0.20.0-2+deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
0.22.1-3+deb12u1.

We recommend that you upgrade your spice-vdagent packages.

For the detailed security status of spice-vdagent please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/spice-vdagent

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmpjQOMACgkQhj1N8u2c
KO8XnA/+NPrf1f4eLfuTf083SG2WlkmZTf5uwvBnYO8hmbWBao8+yItKDRqDHcOz
C/AnaSHeAPukt07jeSq6tB39Lur43k9fB0WcLN25hpe0lglCmE2dGHv1W1zMmLS2
QgWubbRp0H6YAncgzg01IXDOXx3TLymTbY8D9E42plPrwyy6R3RRLklBigrhhkDj
TO72xMZYzzHLPxzblQ5T4zRrazIAA/7z/j3XozhAJO73C6aKBjOcxpwx0KzwxDm6
SZP5Ny3XeAdey+Ia0uv0vgV77tMwmmIdG3Ym/urfvkzrkhWRmpXNJhZqS8vDHsd/
LTH8BaoE+P1YYhp0nZHXm3sCsY1q7uz15IlYrAf3Ag4jOrfUgV4nNQ0kWzlkXOTl
ZJV/70mWDlyP6wVZChQedWvEV1spOCqPxUHieR7Xpga2V+a+CS72aXJUJhGPKHOW
ZowdAv/1k3LjO/BW5b+ROzfrPxkbMYUpgBI4wQi5/2kHu3aPeSiHZrkDnG0tz7YU
0KiG1BG1SFCqoSdZLtBP+ZDW0c5R8tIuCs7AdNkNZzXLZZseFJYKj0K/I1t7SAFm
UZWh9WcW0nD25JChgnyDtvRL5iwT4rAd4Np7FPSJuWOBusPO6NNZead3bfKNfg0k
EwAo5y1inWU9RyyAHAfsCc3+1oi5m1CKZ72ygV0NTgdiS6Jc/KQ=
=venZ
-----END PGP SIGNATURE-----

Reply via email to