Описание
ELSA-2025-22096: tigervnc security update (IMPORTANT)
[1.8.0-33.0.9]
- Fix CVE-2025-62229: xorg-x11-server: Use-after-free in XPresentNotify structures creation [Orabug: 38694278]
- Fix CVE-2025-62230: xorg-x11-server: Use-after-free in Xkb client resource removal
- Fix CVE-2025-62231: xorg-x11-server: Value overflow in Xkb extension XkbSetCompatMap()
[1.8.0-33.0.7]
- Fix CVE-2025-49175, CVE-2025-49176, CVE-2025-49178, CVE-2025-49179, CVE-2025-49180 [Orabug: 38157695]
[1.8.0-33.0.5]
- Fix CVE-2025-26594 xorg-x11-server Use-after-free of the root cursor [Orabug: 37712725]
- Fix CVE-2025-26595 xorg-x11-server Buffer overflow in XkbVModMaskText()
- Fix CVE-2025-26596 xorg-x11-server Heap overflow in XkbWriteKeySyms()
- Fix CVE-2025-26597 xorg-x11-server Buffer overflow in XkbChangeTypesOfKey()
- Fix CVE-2025-26598 xorg-x11-server Out-of-bounds write in CreatePointerBarrierClient()
- Fix CVE-2025-26599 xorg-x11-server Use of uninitialized pointer in compRedirectWindow()
- Fix CVE-2025-26600 xorg-x11-server Use-after-free in PlayReleasedEvents()
- Fix CVE-2025-26601 xorg-x11-server Use-after-free in SyncInitTrigger()
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
tigervnc
1.8.0-33.0.9.el7_9
tigervnc-icons
1.8.0-33.0.9.el7_9
tigervnc-license
1.8.0-33.0.9.el7_9
tigervnc-server
1.8.0-33.0.9.el7_9
tigervnc-server-applet
1.8.0-33.0.9.el7_9
tigervnc-server-minimal
1.8.0-33.0.9.el7_9
tigervnc-server-module
1.8.0-33.0.9.el7_9