{"id":"MGASA-2026-0315","summary":"Updated libvncserver packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\nHeap Out-of-Bounds Read in HandleUltraZipBPP due to unchecked\nsubrectangle count. (CVE-2026-32853)\nNULL pointer dereferences in httpd proxy handlers via malformed\nCONNECT/GET requests. (CVE-2026-32854)\nLibVNCClient Tight Gradient decoding allows malicious server-triggered\nheap/stack OOB writes. (CVE-2026-44988)\nAttacker-controlled heap out-of-bounds write in libvncclient Tight\ndecoder. (CVE-2026-50538)\n","modified":"2026-08-03T19:00:05.507881509Z","published":"2026-08-03T18:47:23Z","upstream":["CVE-2026-32853","CVE-2026-32854","CVE-2026-44988","CVE-2026-50538"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0315.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35628"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/SULCQANWMHMI72ZJZEJWSA2YD3ZSRUKQ/"},{"type":"ADVISORY","url":"https://github.com/LibVNC/libvncserver/security/advisories/GHSA-jcc5-8wj4-7c58"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8463-1"},{"type":"ADVISORY","url":"https://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj"},{"type":"ADVISORY","url":"https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8494-1"},{"type":"ADVISORY","url":"https://github.com/LibVNC/libvncserver/security/advisories/GHSA-v9pm-47h4-jcq8"}],"affected":[{"package":{"name":"libvncserver","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/libvncserver?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.15-2.1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0315.json"}},{"package":{"name":"libvncserver","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libvncserver?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.14-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0315.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}