CVE-2026-57965

Publication date 29 June 2026

Last updated 4 September 2026


Ubuntu priority

Cvss 3 Severity Score

5.1 · Medium

Score breakdown

Description

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This issue requires the SPICE host to be untrusted or compromised for exploitation.

Status

Package Ubuntu Release Status
spice-vdagent 26.04 LTS resolute
Fixed 0.23.0-1ubuntu0.1
25.10 questing Ignored end of life, was needs-triage
24.04 LTS noble
Fixed 0.22.1-4ubuntu0.1
22.04 LTS jammy
Fixed 0.22.1-1ubuntu0.1
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
spice-vdagent

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.1 · Medium

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-8723-1
    • SPICE vdagent vulnerabilities
    • 3 September 2026

Other references


Access our resources on patching vulnerabilities