Red Hat Product Errata RHSA-2026:24341 - Security Advisory Issued: 2026-06-08 Updated: 2026-06-08 RHSA-2026:24341 - Security Advisory Overview Updated Packages Synopsis Important: tigervnc security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for tigervnc is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling (CVE-2026-33999) xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing. (CVE-2026-34000) xorg: xwayland: X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption (CVE-2026-34001) xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling (CVE-2026-34002) xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access (CVE-2026-34003) TigerVNC: x0vncserver: TigerVNC x0vncserver: Information disclosure, data manipulation, and denial of service via incorrect permissions (CVE-2026-34352) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2451106 - CVE-2026-33999 xorg: xwayland: X.Org X server: Denial of Service via integer underflow in XKB compatibility map handling BZ - 2451107 - CVE-2026-34000 xwayland: xorg: X.Org X server: Information disclosure and denial of service via out-of-bounds read in XKB geometry processing. BZ - 2451109 - CVE-2026-34001 xorg: xwayland: X.Org X server: Use-after-free vulnerability leads to server crash and potential memory corruption BZ - 2451112 - CVE-2026-34002 xorg: xwayland: X.Org X server: Information disclosure or Denial of Service via out-of-bounds read in XKB modifier map handling BZ - 2451113 - CVE-2026-34003 xorg: xwayland: X.Org X server: Information exposure and denial of service via out-of-bounds memory access BZ - 2452022 - CVE-2026-34352 TigerVNC: x0vncserver: TigerVNC x0vncserver: Information disclosure, data manipulation, and denial of service via incorrect permissions CVEs CVE-2026-33999 CVE-2026-34000 CVE-2026-34001 CVE-2026-34002 CVE-2026-34003 CVE-2026-34352 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM tigervnc-1.12.0-6.el8_6.17.src.rpm SHA-256: baed018745068a211bcfe52d8d706b689dce6509cbe6488f2be4924c3a22cb3d x86_64 tigervnc-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: ef06186bda0d0aa07fb6967314243806a8c93fcf4a4798565e73a35569b70485 tigervnc-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: dc788df478918dc4969e868b89822ec18cf76ee82c25deb97a8e1fc0748eb1d9 tigervnc-debugsource-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 4154efa5e825adfe16041aab45c17d60e5c2b6849bfbba2ff787835e8b78ca24 tigervnc-icons-1.12.0-6.el8_6.17.noarch.rpm SHA-256: cd41c1a151d1007f8c6cc2df9b899e7e59765220932e1b0bbddadc575cef91a0 tigervnc-license-1.12.0-6.el8_6.17.noarch.rpm SHA-256: c86f4dc3055af7287c34c785782ff6387b687a667a38d90c9c316a91c99f23db tigervnc-selinux-1.12.0-6.el8_6.17.noarch.rpm SHA-256: 54af022e9b1e11b95cafa43a8a3dd3b8251d53eca983912746a0df999039ebc4 tigervnc-server-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 8bebbfc4ecd73ee461369811c46325dcb925f660658fbbcb1d1b9abfd32302b5 tigervnc-server-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 59acf6d0c4cc6b0206ddd2fd08388336775eba9bfc706c2257313208e91ba522 tigervnc-server-minimal-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 5fe50632d2d01dc51e3426de37d7f1956ee17f3cc5d974aaeab11717dceaa4f9 tigervnc-server-minimal-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 54e33eb50b2ad0339ac1bfa8f7728446a9249b1eb7301f84390a9ca011f3a31b tigervnc-server-module-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: bbc591cf19df66a8368c3c8a2720324210374607c9ef7c4d2f0fb4ffd5e5262b tigervnc-server-module-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 1a98a8d413402dc37e7376e2bd5faf31961691611359e4b86d8a9bbce8ae44be Red Hat Enterprise Linux Server - AUS 8.6 SRPM tigervnc-1.12.0-6.el8_6.17.src.rpm SHA-256: baed018745068a211bcfe52d8d706b689dce6509cbe6488f2be4924c3a22cb3d x86_64 tigervnc-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: ef06186bda0d0aa07fb6967314243806a8c93fcf4a4798565e73a35569b70485 tigervnc-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: dc788df478918dc4969e868b89822ec18cf76ee82c25deb97a8e1fc0748eb1d9 tigervnc-debugsource-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 4154efa5e825adfe16041aab45c17d60e5c2b6849bfbba2ff787835e8b78ca24 tigervnc-icons-1.12.0-6.el8_6.17.noarch.rpm SHA-256: cd41c1a151d1007f8c6cc2df9b899e7e59765220932e1b0bbddadc575cef91a0 tigervnc-license-1.12.0-6.el8_6.17.noarch.rpm SHA-256: c86f4dc3055af7287c34c785782ff6387b687a667a38d90c9c316a91c99f23db tigervnc-selinux-1.12.0-6.el8_6.17.noarch.rpm SHA-256: 54af022e9b1e11b95cafa43a8a3dd3b8251d53eca983912746a0df999039ebc4 tigervnc-server-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 8bebbfc4ecd73ee461369811c46325dcb925f660658fbbcb1d1b9abfd32302b5 tigervnc-server-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 59acf6d0c4cc6b0206ddd2fd08388336775eba9bfc706c2257313208e91ba522 tigervnc-server-minimal-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 5fe50632d2d01dc51e3426de37d7f1956ee17f3cc5d974aaeab11717dceaa4f9 tigervnc-server-minimal-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 54e33eb50b2ad0339ac1bfa8f7728446a9249b1eb7301f84390a9ca011f3a31b tigervnc-server-module-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: bbc591cf19df66a8368c3c8a2720324210374607c9ef7c4d2f0fb4ffd5e5262b tigervnc-server-module-debuginfo-1.12.0-6.el8_6.17.x86_64.rpm SHA-256: 1a98a8d413402dc37e7376e2bd5faf31961691611359e4b86d8a9bbce8ae44be The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This Red Hat security advisory addresses multiple vulnerabilities in TigerVNC, including denial of service, information disclosure, and potential memory corruption via flaws in XKB handling within the X.Org X server (CVE-2026-33999, CVSS 7.8 HIGH; CVE-2026-34000, CVSS 6.1 MEDIUM; CVE-2026-34001, CVSS 7.8 HIGH). The update also fixes an incorrect permissions issue in TigerVNC's x0vncserver (CVE-2026-34352). The advisory is rated Important and applies specifically to Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.