[ubuntu/jammy-security] libvncserver 0.9.13+dfsg-3ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Jun 23 14:17:49 UTC 2026


libvncserver (0.9.13+dfsg-3ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: memory leak in rfbClientCleanup()
    - debian/patches/CVE-2020-29260.patch: libvncclient: free vncRec memory in
      rfbClientCleanup() in libvncclient/vncviewer.c.
    - CVE-2020-29260
  * SECURITY UPDATE: Heap Out-of-Bounds Read in HandleUltraZipBPP
    - debian/patches/CVE-2026-32853.patch: libvncclient: add bounds checks to
      UltraZip subrectangle parsing in libvncclient/ultra.c.
    - CVE-2026-32853
  * SECURITY UPDATE: NULL pointer dereferences in httpd proxy handlers
    - debian/patches/CVE-2026-32854.patch: libvncserver: fix NULL pointer
      dereferences in httpd proxy handlers in libvncserver/httpd.c.
    - CVE-2026-32854
  * SECURITY UPDATE: OOB write in Tight Gradient decoding
    - debian/patches/CVE-2026-44988.patch: libvncclient: fix Tight gradient
      decoding overflow in rfb/rfbclient.h, libvncclient/tight.c.
    - CVE-2026-44988

Date: 2026-06-15 16:34:11.554664+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list