-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4755-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
August 25, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : libvncserver
Version : 0.9.13+dfsg-2+deb11u2
CVE ID : CVE-2026-32853 CVE-2026-32854 CVE-2026-44988 CVE-2026-50538
Debian Bug : 1132016 1132017 1138174 1138253
Several vulnerabilities were discovered in libvncserver, a
cross-platform library to implement VNC server or client functionality
in program
CVE-2026-32853
a heap out-of-bounds read vulnerability in the UltraZip encoding
handler that allows a malicious VNC server to cause information
disclosure or application crash. Attackers can exploit improper
bounds checking in the HandleUltraZipBPP() function by
manipulating subrectangle header counts to read beyond the
allocated heap buffer
CVE-2026-32854
null pointer dereference vulnerabilities in the HTTP proxy
handlers within httpProcessInput() in httpd.c that allow remote
attackers to cause a denial of service by sending specially
crafted HTTP requests. Attackers can exploit missing validation of
strchr() return values in the CONNECT and GET proxy handling paths
to trigger null pointer dereferences and crash the server when
httpd and proxy features are enabled.
CVE-2026-44988
LibVNCClient Tight Gradient decoding allows malicious
server-triggered heap/stack out-of-bounds writes
CVE-2026-50538
a malicious (or man-in-the-middle) VNC server can force a
connecting `libvncclient` to write attacker-controlled data past
the end of its framebuffer. This is an out-of-bounds heap write
with attacker-controlled length, contents, and offset.
For Debian 11 bullseye, these problems have been fixed in version
0.9.13+dfsg-2+deb11u2.
We recommend that you upgrade your libvncserver packages.
For the detailed security status of libvncserver please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libvncserver
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqNmSsACgkQhj1N8u2c
KO9W0g//YKA73MJlhROV24z+MrrtQ8B3rABWKviPak8c0mUy2nzWdvHAVcyFuv8o
GOo3FxPXpJC44e9zE31qPzlLPm4FjyHuFUK+eb7nXCEBVgTnHf+nC3glNFyhpaLn
gayvxrnUrOxvcO00z0cdObPEHsrxUSqCSDECgem5MER9MSr1gOaCFl2mcqFJ1rMq
xSS2Nx0f3DpKJSMy+K8Jgipakd3LlrMOaXAdFssdW2FxPrvi4QD1XeeuXZ8mxlrj
i3ZVNpa8mP3iySBN2Y5OYcDCK2pGk4mJisakm7Yxbbe0LTB/MRAtHatw+A0Lzy/G
AkK98ybnOqoK2G7DKDNOI/DqtOCDR4QwJSzzVrVkJc8SXzrd+Sc10p8AvuCePXjq
Elo0EUhyd/N7EcnDkrKppQGk2+5I73pgzl5u1p+5lQ5MPd8SCZEb2xC1tSzK1x6b
q6BUA/W6epqi8hXprNfxDR3+wfXsWrXzJYmHlpjsC6xOr33SscNkgfq8CS3RRi6y
WTFDNrO9WNl58ecBPBw5Ob998j6g7VLtqB/ZX6QExmT2QcEo5vgN5Fjln/tuQr4t
EE7AVzWfbr8B+b7HDMWMKNuaK+5Dc8gAbJWEtLS0X5JQBKAZKjAOtNSe9nvQ6429
VI9+vykaEwuNvx+vfqb1AHPZQAa+G2Bc8zsrrEDZMJi0XFx43ps=
=RVVR
-----END PGP SIGNATURE-----