Views
11

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8723-1 updates `spice-vdagent` for Ubuntu Server 24.04 LTS (noble) to address two security issues. It fixes CVE-2026-57965 and CVE-2026-57966, and requires restarting `spice-vdagent` after updating.

Update Details

Security

  • Fixes an integer overflow in daemon socket buffer size calculation that could let a malicious or compromised SPICE host crash spice-vdagent and cause denial of service (CVE-2026-57965).
  • Fixes improper filename sanitization during file transfers that could let a malicious or compromised SPICE host write arbitrary files on the guest with spice-vdagent privileges (CVE-2026-57966).

Hints

  • After a standard system update, restart spice-vdagent to apply the fixes.
  • For Ubuntu 24.04 LTS (noble), the corrected package version is spice-vdagent 0.22.1-4ubuntu0.1.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 24.04 LTS (Noble Numbat)

Version: spice-vdagent 0.22.1-4ubuntu0.1

Vendor release date: Sep 3, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 6, 2026

Description: Server operating system for Linux infrastructure and workloads.