Debian 11007 Published by

Debian administrators must apply four new security patches targeting critical flaws in spice-vdagent, ImageMagick, GRUB2, and Exim4 this month. The spice-vdagent release closes an integer overflow that crashes virtual machines alongside a path traversal bug permitting unauthorized file writes, while ImageMagick addresses more than twelve issues where malformed images risk denial of service or arbitrary code execution. GRUB2 clears twenty weaknesses tied to UEFI Secure Boot bypasses and system instability, and Exim4 patches two mail server bugs that enabled local privilege escalation. System operators running Debian 10 through 13 should upgrade to the specified package versions right away to block active exploitation.

[DLA 4698-1] spice-vdagent security update
[DLA 4696-1] imagemagick security update
ELA-1783-1 grub2 security update (by )
[DSA 6400-1] exim4 security update




[SECURITY] [DLA 4698-1] spice-vdagent security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4698-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Abhijith PA
July 24, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : spice-vdagent
Version : 0.20.0-2+deb11u1 0.22.1-3+deb12u1
CVE ID : CVE-2026-57965 CVE-2026-57966
Debian Bug : 1141317 1141318

Two vulnerabilities were discovered in spice-vdagent, an agent program
under the SPICE project to ease the remote access to virtual machines
such as clipboard sharing, auto screen resizing.

CVE-2026-57965

A malicious or compromised SPICE host can trigger an integer
overflow by sending a specially crafted message. This
vulnerability can lead to a heap buffer overflow, causing the
spice-vdagent daemon to crash and resulting in a Denial of Service
(DoS) for the virtual machine.

CVE-2026-57966

A path traversal vulnerability was found in spice-vdagent. This
flaw allows a malicious or compromised SPICE host to write
arbitrary files to any location on the guest operating
system. This occurs because the filename provided by the SPICE
host during file transfers is not properly sanitized before being
used. An attacker could exploit this to write to sensitive
locations with the privileges of the spice-vdagent process,
typically the logged-in user.

For Debian 11 bullseye, these problems have been fixed in version
0.20.0-2+deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
0.22.1-3+deb12u1.

We recommend that you upgrade your spice-vdagent packages.

For the detailed security status of spice-vdagent please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/spice-vdagent

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DLA 4696-1] imagemagick security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4696-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Bastien Roucariès
July 23, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : imagemagick
Version : 8:6.9.11.60+dfsg-1.3+deb11u16 8:6.9.11.60+dfsg-1.6+deb12u13
CVE ID : CVE-2026-61464 CVE-2026-61465 CVE-2026-61857 CVE-2026-61858
CVE-2026-61859 CVE-2026-61860 CVE-2026-61862 CVE-2026-61863
CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61868
CVE-2026-61869 CVE-2026-61870 CVE-2026-61872

Multiple security vulnerabilities were discovered in imagemagick, a
software suite used for editing and manipulating digital images, which
could lead to denial of service, information disclosure or potentially
arbitrary code execution if malformed images are processed.

For Debian 11 bullseye, these problems have been fixed in version
8:6.9.11.60+dfsg-1.3+deb11u16.

For Debian 12 bookworm, these problems have been fixed in version
8:6.9.11.60+dfsg-1.6+deb12u13.

We recommend that you upgrade your imagemagick packages.

For the detailed security status of imagemagick please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/imagemagick

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

ELA-1783-1 grub2 security update (by )


Package : grub2

Version : 2.06-3~deb10u5 (buster)

Related CVEs :
CVE-2024-45774
CVE-2024-45775
CVE-2024-45776
CVE-2024-45777
CVE-2024-45778
CVE-2024-45779
CVE-2024-45780
CVE-2024-45781
CVE-2024-45782
CVE-2024-45783
CVE-2025-0622
CVE-2025-0624
CVE-2025-0677
CVE-2025-0678
CVE-2025-0684
CVE-2025-0685
CVE-2025-0686
CVE-2025-0689
CVE-2025-0690
CVE-2025-1118
CVE-2025-1125

Several issues were found in the GRUB2 bootloader, which could result
in crashes and potentially execution of arbitrary code. These could
lead to bypass of UEFI Secure Boot on affected systems.


ELA-1783-1 grub2 security update (by )



[SECURITY] [DSA 6400-1] exim4 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6400-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 24, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : exim4
CVE ID : CVE-2026-66140 CVE-2026-66141

Two vulnerabilities were discovered in Exim, a mail transport agent,
which may result in privilege escalation for a local attacker.

For the stable distribution (trixie), these problems have been fixed in
version 4.98.2-1+deb13u4.

We recommend that you upgrade your exim4 packages.

For the detailed security status of exim4 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/exim4

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/