|
|
Log in / Subscribe / Register

Mageia alert MGASA-2026-0315 (libvncserver)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2026-0315: Updated libvncserver packages fix security vulnerabilities
Date:  Mon, 03 Aug 2026 20:48:07 +0200
Message-ID:  <20260803184807.E2EEF9FEBB@duvel.mageia.org>
Archive-link:  Article

MGASA-2026-0315 - Updated libvncserver packages fix security vulnerabilities Publication date: 03 Aug 2026 URL: https://advisories.mageia.org/MGASA-2026-0315.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-32853, CVE-2026-32854, CVE-2026-44988, CVE-2026-50538 Description: The updated packages fix security vulnerabilities: Heap Out-of-Bounds Read in HandleUltraZipBPP due to unchecked subrectangle count. (CVE-2026-32853) NULL pointer dereferences in httpd proxy handlers via malformed CONNECT/GET requests. (CVE-2026-32854) LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/stack OOB writes. (CVE-2026-44988) Attacker-controlled heap out-of-bounds write in libvncclient Tight decoder. (CVE-2026-50538) References: - https://bugs.mageia.org/show_bug.cgi?id=35628 - https://lists.opensuse.org/archives/list/security-announc... - https://github.com/LibVNC/libvncserver/security/advisorie... - https://ubuntu.com/security/notices/USN-8463-1 - https://github.com/LibVNC/libvncserver/security/advisorie... - https://github.com/LibVNC/libvncserver/security/advisorie... - https://ubuntu.com/security/notices/USN-8494-1 - https://github.com/LibVNC/libvncserver/security/advisorie... - https://www.cve.org/CVERecord?id=CVE-2026-32853 - https://www.cve.org/CVERecord?id=CVE-2026-32854 - https://www.cve.org/CVERecord?id=CVE-2026-44988 - https://www.cve.org/CVERecord?id=CVE-2026-50538 SRPMS: - 10/core/libvncserver-0.9.15-2.1.mga10 - 9/core/libvncserver-0.9.14-1.1.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds