Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:46382: Important: tigervnc security update

This security update addresses multiple critical vulnerabilities (CVE-2026-50256 through CVE-2026-50264) in the xorg-x11-server component used by TigerVNC, including stack buffer overflows and use-after-free flaws that could lead to remote code execution or information disclosure. The CVSS base score for several of these vulnerabilities is 7.8 (High). Affected systems are those running Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On, specifically where the underlying x.org X Server is older than version 21.1.23 or x.org Xwayland is older than version 24.1.12.
Read Full Article →

Red Hat Product Errata RHSA-2026:46382 - Security Advisory Issued: 2026-07-27 Updated: 2026-07-27 RHSA-2026:46382 - Security Advisory Overview Updated Packages Synopsis Important: tigervnc security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for tigervnc is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2485380 - CVE-2026-50256 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch BZ - 2485382 - CVE-2026-50257 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() BZ - 2485383 - CVE-2026-50258 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels BZ - 2485384 - CVE-2026-50259 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing BZ - 2485385 - CVE-2026-50260 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() BZ - 2485386 - CVE-2026-50261 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() BZ - 2485387 - CVE-2026-50262 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes BZ - 2485388 - CVE-2026-50263 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() BZ - 2485389 - CVE-2026-50264 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat CVEs CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM tigervnc-1.11.0-8.el8_4.16.src.rpm SHA-256: e95484143acbb6b42d92522b2815e289155b16df16115e004d74c03721d221b5 x86_64 tigervnc-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 777c37f2036247e07fcd341daa3d6b387cf453f3f762195d4a421ceec5ab919e tigervnc-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: d307d6780f316c637aab9822b16bc435b0f735ad4ba0a10863e6a4fc1d26fe4d tigervnc-debugsource-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 9c9c934c63b70daff919e989bef096fa431c38302f0be37953e4be36db94e87c tigervnc-icons-1.11.0-8.el8_4.16.noarch.rpm SHA-256: af6220a6335f83ac99d2f2c913c9c3bc0e8596714243508f7df1c6a6f7d67d5b tigervnc-license-1.11.0-8.el8_4.16.noarch.rpm SHA-256: 07e426ad8ab2e4a81c0449bdbc3dbcdd557d9ec6ca16ffc8f6104d692b023074 tigervnc-selinux-1.11.0-8.el8_4.16.noarch.rpm SHA-256: e4993e4729102e424bf8e9ee267ac56b44aa193a296d1d9ebbff70c4f6fcac43 tigervnc-server-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 9a183e2f89f7daed6beea555551c22c8ced091918c158c551d1dc4db48a75090 tigervnc-server-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 19b03dbbea28760e698f96c69c80c32568f7ad32f7b564e97b8dab319e293f1f tigervnc-server-minimal-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 2175db26076441d01bb9d0e9498fc3e07b7952425f6eb6b646907857b9cf3511 tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: b46b5afc3805a930c3ba450f41d1253ea6c79c8db984bfa166f1ac641c7388c6 tigervnc-server-module-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 064fca9884eb98bac02984afbc34a91f53470ebf43c5f1f2bacfd8f3f30a4cba tigervnc-server-module-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 16fdecae647ad9c97797e2a022c40aa903ccd3cb7a49bb00bfe4e0a79b7ab695 Red Hat Enterprise Linux Server - AUS 8.4 SRPM tigervnc-1.11.0-8.el8_4.16.src.rpm SHA-256: e95484143acbb6b42d92522b2815e289155b16df16115e004d74c03721d221b5 x86_64 tigervnc-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 777c37f2036247e07fcd341daa3d6b387cf453f3f762195d4a421ceec5ab919e tigervnc-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: d307d6780f316c637aab9822b16bc435b0f735ad4ba0a10863e6a4fc1d26fe4d tigervnc-debugsource-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 9c9c934c63b70daff919e989bef096fa431c38302f0be37953e4be36db94e87c tigervnc-icons-1.11.0-8.el8_4.16.noarch.rpm SHA-256: af6220a6335f83ac99d2f2c913c9c3bc0e8596714243508f7df1c6a6f7d67d5b tigervnc-license-1.11.0-8.el8_4.16.noarch.rpm SHA-256: 07e426ad8ab2e4a81c0449bdbc3dbcdd557d9ec6ca16ffc8f6104d692b023074 tigervnc-selinux-1.11.0-8.el8_4.16.noarch.rpm SHA-256: e4993e4729102e424bf8e9ee267ac56b44aa193a296d1d9ebbff70c4f6fcac43 tigervnc-server-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 9a183e2f89f7daed6beea555551c22c8ced091918c158c551d1dc4db48a75090 tigervnc-server-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 19b03dbbea28760e698f96c69c80c32568f7ad32f7b564e97b8dab319e293f1f tigervnc-server-minimal-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 2175db26076441d01bb9d0e9498fc3e07b7952425f6eb6b646907857b9cf3511 tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: b46b5afc3805a930c3ba450f41d1253ea6c79c8db984bfa166f1ac641c7388c6 tigervnc-server-module-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 064fca9884eb98bac02984afbc34a91f53470ebf43c5f1f2bacfd8f3f30a4cba tigervnc-server-module-debuginfo-1.11.0-8.el8_4.16.x86_64.rpm SHA-256: 16fdecae647ad9c97797e2a022c40aa903ccd3cb7a49bb00bfe4e0a79b7ab695 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article