Updated spice-vdagent packages fix security vulnerabilities
Publication date: 09 Sep 2026Modification date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57965 , CVE-2026-57966
Description
Integer overflow in udscs_write() leading to heap buffer overflow.
(CVE-2026-57965)
Path traversal in file transfer via unsanitized filename.
(CVE-2026-57966)
References
SRPMS
10/core
- spice-vdagent-0.23.0-1.1.mga10
9/core
- spice-vdagent-0.22.1-2.1.mga9