An update that solves one vulnerability can now be installed.. # Security update for tigervnc Announcement ID: SUSE-SU-2026:1303-1 Release Date: 2026-04-13T16:03:04Z Rating: important References: * bsc#1260871 Cross-References: * CVE-2026-34352 CVSS scores: * CVE-2026-34352 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L * CVE-2026-34352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-34352 ( NVD ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for tigervnc fixes the following issues: * CVE-2026-34352: Fixed permissions to prevent other users from observing the screen, or modifying what is sent to the client. (bsc#1260871) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1303=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1303=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1303=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1303=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1303=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64les390x x86_64 i586) * tigervnc-debugsource-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-1.10.1-150400.7.15.1 * tigervnc-debuginfo-1.10.1-150400.7.15.1 * tigervnc-1.10.1-150400.7.15.1 * libXvnc-devel-1.10.1-150400.7.15.1 * libXvnc1-debuginfo-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-1.10.1-150400.7.15.1 * openSUSE Leap 15.4 (noarch) * tigervnc-x11vnc-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-java-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-novnc-1.10.1-150400.7.15.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64 i586) * xorg-x11-Xvnc-module-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-debuginfo-1.10.1-150400.7.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * tigervnc-debugsource-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-1.10.1-150400.7.15.1 * tigervnc-debuginfo-1.10.1-150400.7.15.1 * tigervnc-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-1.10.1-150400.7.15.1 * libXvnc-devel-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-debuginfo-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-1.10.1-150400.7.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * xorg-x11-Xvnc-novnc-1.10.1-150400.7.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * tigervnc-debugsource-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-1.10.1-150400.7.15.1 * tigervnc-debuginfo-1.10.1-150400.7.15.1 * tigervnc-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-1.10.1-150400.7.15.1 * libXvnc-devel-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-debuginfo-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-1.10.1-150400.7.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * xorg-x11-Xvnc-novnc-1.10.1-150400.7.15.1 * SUSE Linux Enterprise Server 15SP4 LTSS (aarch64 ppc64le s390x x86_64) * tigervnc-debugsource-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-1.10.1-150400.7.15.1 * tigervnc-debuginfo-1.10.1-150400.7.15.1 * tigervnc-1.10.1-150400.7.15.1 * libXvnc-devel-1.10.1-150400.7.15.1 * libXvnc1-debuginfo-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-1.10.1-150400.7.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le x86_64) * xorg-x11-Xvnc-module-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-debuginfo-1.10.1-150400.7.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * xorg-x11-Xvnc-novnc-1.10.1-150400.7.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * tigervnc-debugsource-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-1.10.1-150400.7.15.1 * tigervnc-debuginfo-1.10.1-150400.7.15.1 * tigervnc-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-1.10.1-150400.7.15.1 * libXvnc-devel-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-module-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-debuginfo-1.10.1-150400.7.15.1 * xorg-x11-Xvnc-debuginfo-1.10.1-150400.7.15.1 * libXvnc1-1.10.1-150400.7.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * xorg-x11-Xvnc-novnc-1.10.1-150400.7.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34352.html * https://bugzilla.suse.com/show_bug.cgi?id=1260871 . Update for tigervnc resolves important issues regarding screen access permissions on SUSE systems.. tigervnc update, SUSE security patch, remote screen permissions, important security fix. . Severity: Important. LinuxSecurity.com Team
Screen uses ptys with world read/write permissions. . Red Hat, Inc. Security Advisory Package Screen Synopsis screen defaults to not using Unix98 ptys Advisory ID RHSA-1999:042-01 Issue Date 1999-10-20 Updated on Keywords screen unix98 pty permissions Cross references N/A 1. Topic: Screen uses ptys with world read/write permissions. 2. Problem description: The version of screen that shipped with Red Hat Linux 6.1 defaulted to not using Unix98 ptys. Since screen is not setuid root, this means that it leaves the ptys with insecure permissions. The updated packages restore the Unix98 pty support. Thanks go to Chris Evans for noting this vulnerability. Previous versions of Red Hat Linux are not affected by this problem. 3. Bug IDs fixed:(https://bugzilla.redhat.com for more info) 6100 4. Relevant releases/architectures: Red Hat Linux 6.1, for i386 5. Obsoleted by: None 6. Conflicts with: None 7. RPMs required: Intel: screen-3.9.4-3.i386.rpm Source: screen-3.9.4-3.src.rpm Architecture neutral: 8. Solution: For each RPM for your particular architecture, run: rpm -Uvh filename where filename is the name of the RPM. 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 2e5ada61d3d06408bae76bf581d2bf69 screen-3.9.4-3.i386.rpm 09277e5b10b709ac2d974b952cb29e9b screen-3.9.4-3.src.rpm These packages are GPG signed by Red Hat Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig filename If you only wish to verify that each package has not beencorrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg filename 10. References: . Red Hat issued a security advisory for the screen package, emphasizing the fix for inappropriate Unix98 pseudo-terminal permissions and detailing potential vulnerabilities.. Screen Security, Red Hat Security, Unix98 Pty Management, Permissions Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.