tigervnc-1.15.0-7.el9_8.2
エラータID: AXSA:2026-1425:07
以下項目について対処しました。
[Security Fix]
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50256)
- X.org、および Xwayland の miSyncDestroyFence() 関数には、
メモリ領域の解放後利用の問題があるため、ローカルの攻撃者により、
サービス拒否攻撃 (クラッシュの発生)、および特権昇格を可能とする
脆弱性が存在します。(CVE-2026-50257)
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50258)
- X.org、および Xwayland には、スタックベースのバッファオーバー
フローの問題があるため、ローカルの攻撃者により、サービス拒否攻撃
(クラッシュの発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50259)
- X.Org、および Xwayland には、メモリ領域の解放後利用の問題が
あるため、ローカルの攻撃者により、サービス拒否攻撃 (クラッシュの
発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50260)
- X.Org、および Xwayland の SyncChangeCounter() 関数には、メモリ
領域の解放後利用の問題があるため、ローカルの攻撃者により、サービス
拒否攻撃 (クラッシュの発生)、および特権昇格を可能とする脆弱性が
存在します。(CVE-2026-50261)
- X.Org、および Xwayland の __glXDisp_ChangeDrawableAttributes()
関数には、メモリ領域の範囲外読み取りの問題があるため、ローカルの
攻撃者により、情報の漏洩を可能とする脆弱性が存在します。
(CVE-2026-50262)
- X.Org、および Xwayland の CreateSaverWindow() 関数には、メモリ
領域の解放後利用の問題があるため、ローカルの攻撃者により、情報の
漏洩を可能とする脆弱性が存在します。(CVE-2026-50263)
- X.Org、および Xwayland には、メモリ領域の範囲外書き込みの問題
があるため、ローカルの攻撃者により、サービス拒否攻撃 (クラッシュ
の発生)、および特権昇格を可能とする脆弱性が存在します。
(CVE-2026-50264)
パッケージをアップデートしてください。
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name between 257 and 1023 bytes causes the X server to copy that name into the undersized stack buffer without further checks. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, leading to information disclosure. A write path also exists but requires byte-swapped clients which is disabled by default.
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an out-of-bounds heap write. This may be used to crash the server, or for privilege escalation if the X server runs as root.
N/A
SRPMS
- tigervnc-1.15.0-7.el9_8.2.src.rpm
MD5: 624c1f3c81c8d5f89fb4dc863a31b13e
SHA-256: be45378bed39f45c231ffaa8b2d224caf7e1701e9ba0b5cf10d31a03c818eee3
Size: 2.07 MB
Asianux Server 9 for x86_64
- tigervnc-1.15.0-7.el9_8.2.x86_64.rpm
MD5: 137afd6f9aacfb9b02ef3e744d70a0dc
SHA-256: 92016cad22dda4098c354d280ea9a8be75b75e66f6baa737b1f50506852e660e
Size: 369.63 kB - tigervnc-icons-1.15.0-7.el9_8.2.noarch.rpm
MD5: 3f8703bf8781c502d95ca16e29834411
SHA-256: 0fc46c4224381e06adbf829a120253863fba54ecba46a1504609c660557563fe
Size: 37.34 kB - tigervnc-license-1.15.0-7.el9_8.2.noarch.rpm
MD5: dcb265c3a4d654e7d96010b5bee139ca
SHA-256: ae11ea4264db901a76789c2b69b8f380b506ec4eab566ac318d79af81b34eb7f
Size: 17.26 kB - tigervnc-selinux-1.15.0-7.el9_8.2.noarch.rpm
MD5: 88b3475aa4867b345f85a39ba2798502
SHA-256: 79276912084f343ec3f11ca867045b461c9279e8ad1767f19c893f1d1de40464
Size: 27.91 kB - tigervnc-server-1.15.0-7.el9_8.2.x86_64.rpm
MD5: 64c98d8e6457f99aff7049aa7e885cb5
SHA-256: 8161994f58c9232fb8899e737a25d14582cdcbfa2fdc991d224a093375836dbd
Size: 265.66 kB - tigervnc-server-minimal-1.15.0-7.el9_8.2.x86_64.rpm
MD5: 95424cad9078e9ead049d3a419f90564
SHA-256: fb2404d1ff92c6e33d8137c97d2b939db5037affb489e148517226ac83490cdc
Size: 1.18 MB - tigervnc-server-module-1.15.0-7.el9_8.2.x86_64.rpm
MD5: 9498201c9892795498edbc74c2b97b2c
SHA-256: f9464a4ec8c075f6cff62b0e87957bb3ab0b998f8342aa9d5b839f549c8bdf32
Size: 281.00 kB