[CLSA-2025:1744223313] tigervnc: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2025-04-09 18:28:39 UTC
Description:
- CVE-2024-31080: xorg-x11-server: fix heap-based buffer over-read vulnerability in ProcXIGetSelectedEvents() by avoiding byte-swapped length values in replies - CVE-2024-9632: xorg-x11-server: fix improperly tracked allocation size in _XkbSetCompatMap to prevent buffer overflow condition - CVE-2024-31081: xorg-x11-server: fix heap-based buffer over-read vulnerability in ProcXIPassiveGrabDevice() function to prevent memory leakage and segmentation faults by handling byte-swapped length values in replies correctly
Updated packages:
  • tigervnc-1.12.0-13.el9_2.tuxcare.els10.x86_64.rpm
    sha:cc342db7f08c85ec8dfbaa3e8f8f93cdb417c99ed665e7ec9693946a13b10c96
  • tigervnc-icons-1.12.0-13.el9_2.tuxcare.els10.noarch.rpm
    sha:c110d453f26226a08f59af4f216e24f5722c192a2fc92aaf4316a94872a66f9f
  • tigervnc-license-1.12.0-13.el9_2.tuxcare.els10.noarch.rpm
    sha:e16122a3e4e1c0ed934180e426f1b27ab536266deecba5b9a031c23b88bca2b8
  • tigervnc-selinux-1.12.0-13.el9_2.tuxcare.els10.noarch.rpm
    sha:29de83793ea7cc74255dd2cca6e130a62ea479d682db26f4bb6f0dd017f2ae75
  • tigervnc-server-1.12.0-13.el9_2.tuxcare.els10.x86_64.rpm
    sha:73d95afb1e0085fa24600216450850ead15cad84f7497eb04f8ac84d81666cf9
  • tigervnc-server-minimal-1.12.0-13.el9_2.tuxcare.els10.x86_64.rpm
    sha:5a7c7c786791b23b395a18363118b6f2e9d15c4912c3c1cdb1f81bbd1a6ab595
  • tigervnc-server-module-1.12.0-13.el9_2.tuxcare.els10.x86_64.rpm
    sha:930821a6107455a53c7775944103d40fbb8e087cecabd817cbef30a52c81c07d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.