Views
14

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8723-1 updates `spice-vdagent` for Ubuntu Server 22.04 LTS (jammy) to 0.22.1-1ubuntu0.1. It fixes CVE-2026-57965 and CVE-2026-57966, addressing a denial-of-service crash and arbitrary file write risk.

Update Details

Security

  • Fixed an integer overflow in buffer size calculation when writing to the daemon socket, which could let a malicious or compromised SPICE host crash spice-vdagent and cause a denial of service. (CVE-2026-57965)
  • Fixed improper filename sanitization during file transfers, which could let a malicious or compromised SPICE host write arbitrary files on the guest OS with the privileges of the spice-vdagent process. (CVE-2026-57966)

Hints

  • After a standard system update, restart spice-vdagent to apply the changes.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 22.04 LTS (Jammy Jellyfish)

Version: 0.22.1-1ubuntu0.1

Vendor release date: Sep 3, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 4, 2026

Description: Server operating system for Linux infrastructure and workloads.