CVE-2026-57965

EUVD-2026-40049
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This issue requires the SPICE host to be untrusted or compromised for exploitation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.68%
Affected Products (NVD)
VendorProductVersion
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
spice-spacespice-vdagent
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
spice-vdagent
bookworm
vulnerable
bookworm (security)
0.22.1-3+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
0.20.0-2+deb11u1
fixed
forky
0.23.0-3
fixed
sid
0.23.0-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
spice-vdagent
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
ignored
resolute
deferred