[CLSA-2026:1779581754] tigervnc: Fix of CVE-2026-34000
Type:
security
Severity:
Critical
Release date:
2026-05-24 00:15:59 UTC
Description:
- CVE-2026-34000: widen bounds check in _CheckSetGeom() to cover both key alias names (2 * XkbKeyNameLength) and prevent out-of-bounds read of uninitialized memory in XkbAddGeomKeyAlias()
Updated packages:
  • tigervnc-1.12.0-13.el9_2.tuxcare.els24.x86_64.rpm
    sha:8eddb22c37f572995a9f15e7f4060cf04a51ff267f1bb6175a70a605458fc2ff
  • tigervnc-icons-1.12.0-13.el9_2.tuxcare.els24.noarch.rpm
    sha:8f57a00df2ddbee49dfd1ada5fd137f8276e711885ab510b61cc507a10d448a5
  • tigervnc-license-1.12.0-13.el9_2.tuxcare.els24.noarch.rpm
    sha:e8a6420cd6fa249532307c3dc9083512fb72141ccb80ffb4a94b90d803c14210
  • tigervnc-selinux-1.12.0-13.el9_2.tuxcare.els24.noarch.rpm
    sha:b140da2a5ab9a56ed29db5f620fc436d5bd4b1176505f8aaf662eb43944c7baa
  • tigervnc-server-1.12.0-13.el9_2.tuxcare.els24.x86_64.rpm
    sha:40dc3ebb21c47441c829c5dbb042a9192014a525ec5e90ad0707a931a2f7e365
  • tigervnc-server-minimal-1.12.0-13.el9_2.tuxcare.els24.x86_64.rpm
    sha:68281e115f71ce810af796883d0324c1ae7112022d87b170dcc5bf358beb9727
  • tigervnc-server-module-1.12.0-13.el9_2.tuxcare.els24.x86_64.rpm
    sha:9fab35165e8e55ae955165be01bbee4eb00c2668aff41c59972d42b02551351e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.