Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:46460: Important: tigervnc security update

This security update addresses multiple high-severity vulnerabilities (CVSS 7.8) in the xorg-x11-server component used by TigerVNC, including stack buffer overflows and use-after-free flaws that could lead to code execution or information disclosure. The affected versions are x.org X Server prior to version 21.1.23 and Xwayland prior to version 24.1.12, as deployed in Red Hat Enterprise Linux 7.0, 8.0, and 9.0. The fix is included in the provided Red Hat update packages, requiring an immediate patch application to the affected systems.
Read Full Article →

Red Hat Product Errata RHSA-2026:46460 - Security Advisory Issued: 2026-07-27 Updated: 2026-07-27 RHSA-2026:46460 - Security Advisory Overview Updated Packages Synopsis Important: tigervnc security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for tigervnc is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263) xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2485380 - CVE-2026-50256 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch BZ - 2485382 - CVE-2026-50257 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() BZ - 2485383 - CVE-2026-50258 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels BZ - 2485384 - CVE-2026-50259 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing BZ - 2485385 - CVE-2026-50260 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() BZ - 2485386 - CVE-2026-50261 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() BZ - 2485387 - CVE-2026-50262 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes BZ - 2485388 - CVE-2026-50263 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() BZ - 2485389 - CVE-2026-50264 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat CVEs CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 SRPM tigervnc-1.12.0-6.el8_6.18.src.rpm SHA-256: 18efa98ad17926269ec4270b8538156d62964c892f6be015a7fc54531b1f4378 x86_64 tigervnc-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: f1964cc4876ebf5364a265f36e1f00ad7d3a42ea50709fd83d406222df4ed2f0 tigervnc-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: ad21ca23a462b5f7537ced3f29c1685c3a8cb1ae2c57fb13c3b8cb513e2b9573 tigervnc-debugsource-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 6dab277a191785605233e06ca2c38e617e3aae41e0560f302450abaa5bc56563 tigervnc-icons-1.12.0-6.el8_6.18.noarch.rpm SHA-256: 93895c871d2f3b2fc7397700bbad1b58dd46ec868c8772e4370336505d174e29 tigervnc-license-1.12.0-6.el8_6.18.noarch.rpm SHA-256: 9fb224129dd7c9525a4b03aef7c08209dab15a412410de28177fffdde3b0e3fa tigervnc-selinux-1.12.0-6.el8_6.18.noarch.rpm SHA-256: be04446171a46f5f94402d30f719bdfb3469a56268993907d1fb2d95002afedc tigervnc-server-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 11aa3d910fce98fc5ed8c590327a63476150fb92f540762aa7cb972455b6f1c4 tigervnc-server-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: d6f6075ea4b2f747f169c9ac3e6c411150b8191c152b41ba356935cebaca3211 tigervnc-server-minimal-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 53d7dd973ffb44c3e9000e6b7c0ca11f94d7213918b26f7e012600e7be5b79a1 tigervnc-server-minimal-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 3b7257193e1d7928cae8bcefd5af3f292d2f5980e027d911752d1d7d473994ab tigervnc-server-module-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 1301a70a938b13dd0e236330b8871b0749afb1bcff3552ba382258d1725c1f0c tigervnc-server-module-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: c71fdb310f25cb89858a7cf3cc2f0fce5003936d16d3d295f594b6abee5c8503 Red Hat Enterprise Linux Server - AUS 8.6 SRPM tigervnc-1.12.0-6.el8_6.18.src.rpm SHA-256: 18efa98ad17926269ec4270b8538156d62964c892f6be015a7fc54531b1f4378 x86_64 tigervnc-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: f1964cc4876ebf5364a265f36e1f00ad7d3a42ea50709fd83d406222df4ed2f0 tigervnc-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: ad21ca23a462b5f7537ced3f29c1685c3a8cb1ae2c57fb13c3b8cb513e2b9573 tigervnc-debugsource-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 6dab277a191785605233e06ca2c38e617e3aae41e0560f302450abaa5bc56563 tigervnc-icons-1.12.0-6.el8_6.18.noarch.rpm SHA-256: 93895c871d2f3b2fc7397700bbad1b58dd46ec868c8772e4370336505d174e29 tigervnc-license-1.12.0-6.el8_6.18.noarch.rpm SHA-256: 9fb224129dd7c9525a4b03aef7c08209dab15a412410de28177fffdde3b0e3fa tigervnc-selinux-1.12.0-6.el8_6.18.noarch.rpm SHA-256: be04446171a46f5f94402d30f719bdfb3469a56268993907d1fb2d95002afedc tigervnc-server-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 11aa3d910fce98fc5ed8c590327a63476150fb92f540762aa7cb972455b6f1c4 tigervnc-server-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: d6f6075ea4b2f747f169c9ac3e6c411150b8191c152b41ba356935cebaca3211 tigervnc-server-minimal-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 53d7dd973ffb44c3e9000e6b7c0ca11f94d7213918b26f7e012600e7be5b79a1 tigervnc-server-minimal-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 3b7257193e1d7928cae8bcefd5af3f292d2f5980e027d911752d1d7d473994ab tigervnc-server-module-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: 1301a70a938b13dd0e236330b8871b0749afb1bcff3552ba382258d1725c1f0c tigervnc-server-module-debuginfo-1.12.0-6.el8_6.18.x86_64.rpm SHA-256: c71fdb310f25cb89858a7cf3cc2f0fce5003936d16d3d295f594b6abee5c8503 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article