Red Hat Security Advisory: tigervnc security update
🔗 CVE IDs covered (18)
📋 Description
CVE-2022-4283 — xorg-x11-server: XkbGetKbdByName use-after-free CVE-2022-46340 — xorg-x11-server: XTestSwapFakeInput stack overflow CVE-2022-46341 — xorg-x11-server: XIPassiveUngrab out-of-bounds access CVE-2022-46342 — xorg-x11-server: XvdiSelectVideoNotify use-after-free CVE-2022-46343 — xorg-x11-server: ScreenSaverSetAttributes use-after-free CVE-2022-46344 — xorg-x11-server: XIChangeProperty out-of-bounds access CVE-2023-0494 — xorg-x11-server: DeepCopyPointerClasses use-after-free leads to privilege elevation CVE-2023-1393 — xorg-x11-server: X.Org Server Overlay Window Use-After-Free Local Privilege Escalation Vulnerability CVE-2023-5367 — xorg-x11-server: Out-of-bounds write in XIChangeDeviceProperty/RRChangeOutputProperty CVE-2023-6478 — xorg-x11-server: out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty CVE-2023-6816 — xorg-x11-server: Heap buffer overflow in DeviceFocusEvent and ProcXIQueryPointer CVE-2024-0229 — xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access CVE-2024-9632 — xorg-x11-server: tigervnc: heap-based buffer overflow privilege escalation vulnerability CVE-2024-21885 — xorg-x11-server: heap buffer overflow in XISendDeviceHierarchyEvent CVE-2024-21886 — xorg-x11-server: heap buffer overflow in DisableDevice CVE-2024-31080 — xorg-x11-server: Heap buffer overread/data leakage in ProcXIGetSelectedEvents CVE-2024-31081 — xorg-x11-server: Heap buffer overread/data leakage in ProcXIPassiveGrabDevice CVE-2024-31083 — xorg-x11-server: Use-after-free in ProcRenderAddGlyphs
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2025:12751
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151758
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165995
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180288
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2243091
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253298
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256540
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2256690
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2257691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2317233
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_12751.json