MGASA-2026-0088 - Updated tigervnc packages fix security vulnerability. MGASA-2026-0088 - Updated tigervnc packages fix security vulnerability Publication date: 07 Apr 2026 URL: https://advisories.mageia.org/MGASA-2026-0088.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-34352 Description: In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions. (CVE-2026-34352) References: - https://bugs.mageia.org/show_bug.cgi?id=35311 - https://www.openwall.com/lists/oss-security/2026/03/26/7 - https://www.cve.org/CVERecord?id=CVE-2026-34352 SRPMS: - 9/core/tigervnc-1.13.1-2.10.mga9 . Updated tigervnc packages in Mageia address a critical security issue allowing screen manipulation and crashing.. tigervnc security. . Severity: Critical. LinuxSecurity.com Team
Jason A. Donenfeld found an ansi escape sequence injection into software-properties, a manager for apt repository sources. An attacker could manipulate the screen of a user prompted to install an additional repository (PPA). . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2339-1
Get the latest Linux and open source security news straight to your inbox.