Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 23 articles for you...
89

Fedora 43 TigerVNC Security Update for CVE Reference 2026-492e92b32d

Update to xserver 21.1.22, CVE fix for: CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, CVE-2026-34003. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-492e92b32d 2026-04-25 01:42:21.312792+00:00 -------------------------------------------------------------------------------- Name : tigervnc Product : Fedora 43 Version : 1.16.2 Release : 2.fc43 URL : https://www.tigervnc.com Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. -------------------------------------------------------------------------------- Update Information: Update to xserver 21.1.22, CVE fix for: CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, CVE-2026-34003 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 16 2026 Jan Grulich - 1.16.2-2 - Fixes CVEs: CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, CVE-2026-34003 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-492e92b32d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fix for multiple CVEs in TigerVNC on Fedora 43 to enhance remote display security and functionality.. TigerVNC Fedora CVEs remote display security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 25, 2026 Important Fedora
89

Fedora 42: TigerVNC Important CVE Fixes for Remote Access 2025-f59b250c31

Fix recent xorg-x11-server CVEs: Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f59b250c31 2025-12-03 01:05:22.296747+00:00 -------------------------------------------------------------------------------- Name : tigervnc Product : Fedora 42 Version : 1.15.0 Release : 10.fc42 URL : http://www.tigervnc.com Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. -------------------------------------------------------------------------------- Update Information: Fix recent xorg-x11-server CVEs: Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231 -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Jan Grulich - 1.15.0-10 - Rebuild (xorg-x11-server) Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231 * Tue Nov 11 2025 Cristian Le - 1.15.0-9 - Allow to build with CMake 4.0 (rhbz#2381485) * Wed Oct 15 2025 Dominik Mierzejewski - 1.15.0-8 - Rebuilt for FFmpeg 8 * Fri Jul 25 2025 Fedora Release Engineering - 1.15.0-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375539 - CVE-2025-49180 tigervnc: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375539 [ 2 ] Bug #2375544 - CVE-2025-49179 tigervnc: Integer overflow in X Record extension [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375544 [ 3 ] Bug #2375554 - CVE-2025-49176 tigervnc: Integer Overflow in Big Requests Extension [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375554 [ 4 ] Bug #2375557 - CVE-2025-49175 tigervnc: Out-of-Bounds Read in X Rendering Extension Animated Cursors [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375557 [ 5 ] Bug #2375561 - CVE-2025-49177 tigervnc: Data Leak in XFIXES Extension's XFixesSetClientDisconnectMode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375561 [ 6 ] Bug #2375564 - CVE-2025-49178 tigervnc: Unprocessed Client Request Due to Bytes to Ignore [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375564 [ 7 ] Bug #2407297 - CVE-2025-62231 tigervnc: Value overflow in XkbSetCompatMap() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2407297 [ 8 ] Bug #2407299 - CVE-2025-62230 tigervnc: Use-after-free in Xkb client resource removal [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2407299 [ 9 ] Bug #2407304 - CVE-2025-62229 tigervnc: Use-after-free in XPresentNotify structure creation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2407304 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f59b250c31' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 TigerVNC update fixes critical CVEs to enhance remote display security. Install with dnf now!. TigerVNC Fedora Update CVEs Remote Access. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 03, 2025 Important Fedora
89

Fedora 43: TigerVNC Moderate Use-After-Free Issues FEDORA-2025-e0c935675d

Fix recent xorg-x11-server CVEs: Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e0c935675d 2025-12-03 00:52:00.122524+00:00 -------------------------------------------------------------------------------- Name : tigervnc Product : Fedora 43 Version : 1.15.0 Release : 10.fc43 URL : http://www.tigervnc.com Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. -------------------------------------------------------------------------------- Update Information: Fix recent xorg-x11-server CVEs: Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231 -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Jan Grulich - 1.15.0-10 - Rebuild (xorg-x11-server) Fixes: CVE-2025-62229 CVE-2025-62230 CVE-2025-62231 * Tue Nov 11 2025 Cristian Le - 1.15.0-9 - Allow to build with CMake 4.0 (rhbz#2381485) * Wed Oct 15 2025 Dominik Mierzejewski - 1.15.0-8 - Rebuilt for FFmpeg 8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375539 - CVE-2025-49180 tigervnc: Integer Overflow in X Resize, Rotate and Reflect (RandR) Extension [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375539 [ 2 ] Bug #2375544 - CVE-2025-49179 tigervnc: Integer overflow in X Record extension [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375544 [ 3 ] Bug #2375554 - CVE-2025-49176 tigervnc: Integer Overflow in Big Requests Extension [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375554 [ 4 ] Bug #2375557 - CVE-2025-49175 tigervnc: Out-of-Bounds Read in X Rendering Extension Animated Cursors [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375557 [ 5 ] Bug #2375561 - CVE-2025-49177 tigervnc: Data Leak in XFIXES Extension's XFixesSetClientDisconnectMode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375561 [ 6 ] Bug #2375564 - CVE-2025-49178 tigervnc: Unprocessed Client Request Due to Bytes to Ignore [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2375564 [ 7 ] Bug #2407297 - CVE-2025-62231 tigervnc: Value overflow in XkbSetCompatMap() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2407297 [ 8 ] Bug #2407299 - CVE-2025-62230 tigervnc: Use-after-free in Xkb client resource removal [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2407299 [ 9 ] Bug #2407304 - CVE-2025-62229 tigervnc: Use-after-free in XPresentNotify structure creation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2407304 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e0c935675d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fixes CVEs for TigerVNC in Fedora 43, addressing critical security issues like use-after-free vulnerabilities.. TigerVNC update, Fedora 43 advisory, remote desktop security, CVE mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 03, 2025 Important Fedora
89

Fedora 42: tigervnc critical CVE fixes for multiple xorg issues

xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-984e1cee93 2025-06-28 01:13:17.787622+00:00 -------------------------------------------------------------------------------- Name : tigervnc Product : Fedora 42 Version : 1.15.0 Release : 6.fc42 URL : https://tigervnc.org/ Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. -------------------------------------------------------------------------------- Update Information: xorg-x11-server CVE fix for CVE-2025-49175, CVE-2025-49176, CVE-2025-49177, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 23 2025 Jan Grulich - 1.15.0-6 - Rebuild (xorg-x11-server) Fixes: CVE-2025-49175 / CVE-2025-49176 / CVE-2025-49177 CVE-2025-49178 / CVE-2025-49179 / CVE-2025-49180 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-984e1cee93' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 issues urgent patch for tigervnc tackling several xorg security flaws. Update advised without delay!. Fedora Security,tigervnc update,CVE-2025 fix,remote display system,security notifications. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 28, 2025 Critical Fedora
89

Fedora 40: tigervnc 2025-a87bc329fe Security Advisory Updates

Fixes for xorg-x11-server CVEs.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a87bc329fe 2025-03-13 01:47:29.556428+00:00 -------------------------------------------------------------------------------- Name : tigervnc Product : Fedora 40 Version : 1.15.0 Release : 2.fc40 URL : https://tigervnc.org/ Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. -------------------------------------------------------------------------------- Update Information: Fixes for xorg-x11-server CVEs. -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 3 2025 Jan Grulich - 1.15.0-2 - Rebuild (xorg-x11-server) Fixes CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2349366 - CVE-2025-26598 tigervnc: Out-of-bounds write in CreatePointerBarrierClient() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349366 [ 2 ] Bug #2349369 - CVE-2025-26594 tigervnc: Use-after-free of the root cursor [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349369 [ 3 ] Bug #2349372 - CVE-2025-26596 tigervnc: Heap overflow in XkbWriteKeySyms() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349372 [ 4 ] Bug #2349375 - CVE-2025-26595 tigervnc: Buffer overflow in XkbVModMaskText() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349375 [ 5 ]Bug #2349378 - CVE-2025-26597 tigervnc: Buffer overflow in XkbChangeTypesOfKey() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349378 [ 6 ] Bug #2349455 - CVE-2025-26599 tigervnc: Use of uninitialized pointer in compRedirectWindow() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349455 [ 7 ] Bug #2349460 - CVE-2025-26601 tigervnc: Use-after-free in SyncInitTrigger() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349460 [ 8 ] Bug #2349461 - CVE-2025-26600 tigervnc: Use-after-free in PlayReleasedEvents() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2349461 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a87bc329fe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Addressing critical security alerts for Tigervnc in Fedora 40 associated with xorg-x11-server vulnerabilities.. fixes, xorg-x11-server, --------------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 13, 2025 Critical Fedora
89

Fedora 38 FEDORA-2023-dbacf5d9f6 Moderate: Tigervnc Out-of-Bounds Fix

Fixes CVEs reported against Xserver.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-dbacf5d9f6 2023-11-13 01:29:00.044871 -------------------------------------------------------------------------------- Name : tigervnc Product : Fedora 38 Version : 1.13.1 Release : 6.fc38 URL : https://tigervnc.org/ Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. -------------------------------------------------------------------------------- Update Information: Fixes CVEs reported against Xserver. -------------------------------------------------------------------------------- ChangeLog: * Thu Nov 2 2023 Jan Grulich - 1.13.1-6 - Fix CVE-2023-5380 and CVE-2023-5367 (rebuild with fixed Xorg) * Wed Oct 18 2023 Kalev Lember - 1.13.1-5 - Drop unrecognized configure options - Add buildrequires to get correct font and xkb directories from pkg-config - Re-enable server in flatpak builds and fix the build * Sat Jul 22 2023 Fedora Release Engineering - 1.13.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2247468 - CVE-2023-5367 tigervnc: xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2247468 [ 2 ] Bug #2247469 - CVE-2023-5380 tigervnc: xorg-x11-server: Use-after-free bug in DestroyWindow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2247469 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-dbacf5d9f6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The Fedora 38 release for tigervnc resolves urgent concerns linked to Xserver CVEs, promoting improved security features and stability enhancements.. Fedora Tigervnc Update, Xserver Security Patch, Remote Access Fixes. . LinuxSecurity.com Team

Calendar 2 Nov 13, 2023 Fedora
98

Red Hat 9.0: RHSA-2023-1599-01 Critical: tigervnc Local Escalation

An update for tigervnc is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: tigervnc security update Advisory ID: RHSA-2023:1599-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1599 Issue date: 2023-04-04 CVE Names: CVE-2023-1393 ==================================================================== 1. Summary: An update for tigervnc is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients. Security Fix(es): * xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability (CVE-2023-1393) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2180288 - CVE-2023-1393 xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.9.0): Source: tigervnc-1.11.0-22.el9_0.2.src.rpm aarch64: tigervnc-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-debuginfo-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-debugsource-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-server-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-server-debuginfo-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-server-minimal-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-server-minimal-debuginfo-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-server-module-1.11.0-22.el9_0.2.aarch64.rpm tigervnc-server-module-debuginfo-1.11.0-22.el9_0.2.aarch64.rpm noarch: tigervnc-icons-1.11.0-22.el9_0.2.noarch.rpm tigervnc-license-1.11.0-22.el9_0.2.noarch.rpm tigervnc-selinux-1.11.0-22.el9_0.2.noarch.rpm ppc64le: tigervnc-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-debuginfo-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-debugsource-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-server-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-server-debuginfo-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-server-minimal-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-server-minimal-debuginfo-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-server-module-1.11.0-22.el9_0.2.ppc64le.rpm tigervnc-server-module-debuginfo-1.11.0-22.el9_0.2.ppc64le.rpm s390x: tigervnc-1.11.0-22.el9_0.2.s390x.rpm tigervnc-debuginfo-1.11.0-22.el9_0.2.s390x.rpm tigervnc-debugsource-1.11.0-22.el9_0.2.s390x.rpm tigervnc-server-1.11.0-22.el9_0.2.s390x.rpm tigervnc-server-debuginfo-1.11.0-22.el9_0.2.s390x.rpm tigervnc-server-minimal-1.11.0-22.el9_0.2.s390x.rpm tigervnc-server-minimal-debuginfo-1.11.0-22.el9_0.2.s390x.rpm tigervnc-server-module-1.11.0-22.el9_0.2.s390x.rpm tigervnc-server-module-debuginfo-1.11.0-22.el9_0.2.s390x.rpm x86_64: tigervnc-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-debuginfo-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-debugsource-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-server-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-server-debuginfo-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-server-minimal-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-server-minimal-debuginfo-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-server-module-1.11.0-22.el9_0.2.x86_64.rpm tigervnc-server-module-debuginfo-1.11.0-22.el9_0.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-1393 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZCw/ItzjgjWX9erEAQiNEw/+NSKeID9MFl/F+AZhYIVB0rHAqfGN3CO3 rMSJPbBZ+Fo5hphZLuEjuZquEWFMLZ/WbjFUlAjNdP2gHF8ewCI6ErMQ5dHOTrg5 /EOKbVF2PAXZPl+7jEwVWX2Uny4cKPvWiNpoPUmRnUbjFXvElwZMOi9lFMWr011W 2JWPazQ8UVlQHFh3Oo/XfONulbxgRjUafBxVSJWPtRFiVmgSWSXnyz/jT7z8Trdn VmvHQJYVh/v2pRF4/lnO6BhlLDBA8BGaLfa7TYgQ+GP2kEKPvz/AUuLS1Da1ytk8 KPgGWpOcUJHC2mHQJE5QLRW7kgLl09q+SRXTEbNFBiCJDBlxlyvMR7bRxkFL//Lj WIaMADn/6Aa5AlX2JM+CoXjIsMjDwPR1WDUGGcvy9y+WkNK2a7Tmn1jjIzYo3Cz8 EzTdya3dVGz2ZAaYRXPvUWrpB0vRpUwVfByhPnhaZBK/eOP7blgjcpa/4bQYsjZo yv7Iz+W5vhYtzOiUn/8eFgGL2/pUXC76CWm5C/El7ZxmGoMvdGfCQgIYXIUH5SuL eOwUn+7Nf8IaYtbKkTW7oc4ArR7PMarDHvdbE4hN4e5oHQJYgdxEQeMBZy/BKC9n wNRXtYbufEEQt268rcF1iFTSGDwVHy9uIfO8QnymD9cF1DPMWurRr+X3E1pByS/s 5t++SrIu+rc=LUkX -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest release of tigervnc for Red Hat Enterprise Linux 9.0 brings significant updates. Enhance your system's safety by upgrading today.. tigervnc update, Red Hat security, privilege escalation, linux update, enterprise security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 04, 2023 Important Red Hat
219

Rocky Linux: RLSA-2023:0622 Important: Tigervnc Privilege Escalation

Important: tigervnc security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:0622", "synopsis": "Important: tigervnc security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for tigervnc.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.\n\nSecurity Fix(es):\n\n* xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation (CVE-2023-0494)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2165995", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2165995", "description": ""}], "cves": [{"name": "CVE-2023-0494", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0494", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}], "references": [], "publishedAt": "2023-02-16T06:36:03.545804Z", "rpms": {"Rocky Linux 9": {"nvras": ["tigervnc-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-0:1.12.0-5.el9_1.1.src.rpm", "tigervnc-debuginfo-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-debuginfo-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-debuginfo-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-debugsource-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-debugsource-0:1.12.0-5.el9_1.1.ppc64le.rpm","tigervnc-debugsource-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-icons-0:1.12.0-5.el9_1.1.noarch.rpm", "tigervnc-license-0:1.12.0-5.el9_1.1.noarch.rpm", "tigervnc-selinux-0:1.12.0-5.el9_1.1.noarch.rpm", "tigervnc-server-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-server-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-server-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-server-debuginfo-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-server-debuginfo-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-server-debuginfo-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-server-minimal-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-server-minimal-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-server-minimal-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-server-minimal-debuginfo-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-server-minimal-debuginfo-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-server-minimal-debuginfo-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-server-module-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-server-module-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-server-module-0:1.12.0-5.el9_1.1.s390x.rpm", "tigervnc-server-module-debuginfo-0:1.12.0-5.el9_1.1.aarch64.rpm", "tigervnc-server-module-debuginfo-0:1.12.0-5.el9_1.1.ppc64le.rpm", "tigervnc-server-module-debuginfo-0:1.12.0-5.el9_1.1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An urgent security notice for Rocky Linux concerning tigervnc, highlighting a significant risk of privilege escalation.. TigerVNC Security, Rocky Linux Update, Privilege Escalation Risk. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 16, 2023 Important Rocky Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here