This update for spice-vdagent fixes the following issues:
CVE-2026-57965: integer overflow in udscs_write() allows a compromised SPICE host to crash the spice-vdagent
daemon via a specially crafted message that triggers a heap buffer overflow (bsc#1269553).
CVE-2026-57966: improper sanitization allows a compromised SPICE host to write arbitrary files to any location on the
guest operating system (bsc#1269554).