Dear stable release managers, please consider spice-vdagent/0.22.1-4.1+deb13u1
for trixie
[ Reason ]
Two CVEs CVE-2026-57965 and CVE-2026-57966 reported against spice-vdagent
[ Impact ]
CVE-2026-57965 is a heap buffer overflow and CVE-2026-57966 is path
traversal vulnerability.
[ Tests ]
The package lack testsuite.
[ Risks ]
The security fix backported from upstream version 0.23.0 and the changes
compared to the version in stable is minimal and because of that patch fit
nicely
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
(Explain *all* the changes)
[ Other info ]
(Anything else the release team should know.)