Ubuntu Security Notices USN-8494-1 USN-8494-1: LibVNCServer vulnerability Publication date 2 July 2026 Overview LibVNCServer could be made to crash or run programs if it received specially crafted network traffic. Releases 26.04 LTS 25.10 24.04 LTS 22.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages libvncserver - vnc server library Details It was discovered that LibVNCServer incorrectly handled the Tight decoder in libvncclient. A remote attacker could use this issue to cause LibVNCServer to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that LibVNCServer incorrectly handled the Tight decoder in libvncclient. A remote attacker could use this issue to cause LibVNCServer to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute libvncclient1 – 0.9.15+dfsg-3ubuntu0.2 libvncserver1 – 0.9.15+dfsg-3ubuntu0.2 25.10 questing libvncclient1 – 0.9.15+dfsg-1ubuntu0.2 libvncserver1 – 0.9.15+dfsg-1ubuntu0.2 24.04 LTS noble libvncclient1 – 0.9.14+dfsg-1ubuntu0.2 libvncserver1 – 0.9.14+dfsg-1ubuntu0.2 22.04 LTS jammy libvncclient1 – 0.9.13+dfsg-3ubuntu0.2 libvncserver1 – 0.9.13+dfsg-3ubuntu0.2 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-50538 CVE-2026-50538
A vulnerability (CVE-2026-50538) in LibVNCServer's Tight decoder within libvncclient allows a remote attacker to send specially crafted network traffic, causing a denial of service or arbitrary code execution. The flaw affects multiple Ubuntu LTS releases, including 22.04 LTS, 24.04 LTS, 25.10, and 26.04 LTS. The issue is corrected by updating the `libvncclient1` and `libvncserver1` packages to the specific versions listed in the USN, such as version `0.9.15+dfsg-3ubuntu0.2` for Ubuntu 26.04 LTS.