Medium severity5.1NVD Advisory· Published Jun 29, 2026· Updated Jul 8, 2026
CVE-2026-57965
CVE-2026-57965
Description
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This issue requires the SPICE host to be untrusted or compromised for exploitation.
Affected products
10- cpe:2.3:a:spice-space:spice-vdagent:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/spice-vdagent&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/spice-vdagent&distro=openSUSE%20Tumbleweed
< 0.22.1-160000.3.1+ 1 more
- (no CPE)range: < 0.22.1-160000.3.1
- (no CPE)range: < 0.23.0-4.1
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2026-57965nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.