tigervnc-1.15.0-7.el9_8.2

エラータID: AXSA:2026-1425:07

Release date: 
Tuesday, August 4, 2026 - 04:14
Subject: 
tigervnc-1.15.0-7.el9_8.2
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.

Security Fix(es):

* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263)
* xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-50256
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50257
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50258
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50259
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50260
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50261
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
CVE-2026-50262
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
CVE-2026-50263
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
CVE-2026-50264
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tigervnc-1.15.0-7.el9_8.2.src.rpm
    MD5: 624c1f3c81c8d5f89fb4dc863a31b13e
    SHA-256: be45378bed39f45c231ffaa8b2d224caf7e1701e9ba0b5cf10d31a03c818eee3
    Size: 2.07 MB

Asianux Server 9 for x86_64
  1. tigervnc-1.15.0-7.el9_8.2.x86_64.rpm
    MD5: 137afd6f9aacfb9b02ef3e744d70a0dc
    SHA-256: 92016cad22dda4098c354d280ea9a8be75b75e66f6baa737b1f50506852e660e
    Size: 369.63 kB
  2. tigervnc-icons-1.15.0-7.el9_8.2.noarch.rpm
    MD5: 3f8703bf8781c502d95ca16e29834411
    SHA-256: 0fc46c4224381e06adbf829a120253863fba54ecba46a1504609c660557563fe
    Size: 37.34 kB
  3. tigervnc-license-1.15.0-7.el9_8.2.noarch.rpm
    MD5: dcb265c3a4d654e7d96010b5bee139ca
    SHA-256: ae11ea4264db901a76789c2b69b8f380b506ec4eab566ac318d79af81b34eb7f
    Size: 17.26 kB
  4. tigervnc-selinux-1.15.0-7.el9_8.2.noarch.rpm
    MD5: 88b3475aa4867b345f85a39ba2798502
    SHA-256: 79276912084f343ec3f11ca867045b461c9279e8ad1767f19c893f1d1de40464
    Size: 27.91 kB
  5. tigervnc-server-1.15.0-7.el9_8.2.x86_64.rpm
    MD5: 64c98d8e6457f99aff7049aa7e885cb5
    SHA-256: 8161994f58c9232fb8899e737a25d14582cdcbfa2fdc991d224a093375836dbd
    Size: 265.66 kB
  6. tigervnc-server-minimal-1.15.0-7.el9_8.2.x86_64.rpm
    MD5: 95424cad9078e9ead049d3a419f90564
    SHA-256: fb2404d1ff92c6e33d8137c97d2b939db5037affb489e148517226ac83490cdc
    Size: 1.18 MB
  7. tigervnc-server-module-1.15.0-7.el9_8.2.x86_64.rpm
    MD5: 9498201c9892795498edbc74c2b97b2c
    SHA-256: f9464a4ec8c075f6cff62b0e87957bb3ab0b998f8342aa9d5b839f549c8bdf32
    Size: 281.00 kB