Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57964

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in spice-vdagent. On macOS and BSD platforms, an unprivileged local user can bypass authentication by connecting to the Unix Domain Socket Client/Server (UDSCS) socket. This allows the unauthorized user to receive host-to-guest messages, including clipboard data and file transfers, inject clipboard data to the SPICE host, and prevent the legitimate agent from functioning.

Отчет

Red Hat products are not affected by this CVE as the vulnerable code is not present in Red Hat's shipped versions of spice-vdagent.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10spice-vdagentNot affected
Red Hat Enterprise Linux 6spice-vdagentNot affected
Red Hat Enterprise Linux 7spice-vdagentNot affected
Red Hat Enterprise Linux 8mingw-spice-vdagentNot affected
Red Hat Enterprise Linux 8spice-vdagentNot affected
Red Hat Enterprise Linux 9spice-vdagentNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2493580spice-vdagent: Authentication bypass on macOS/BSD due to dummy session info

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

[Unknown description]

debian

Описание отсутствует

5.3 Medium

CVSS3