Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:22167 - Security Advisory
Issued:
2025-11-26
Updated:
2025-11-26

RHSA-2025:22167 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: tigervnc security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for tigervnc is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.

Security Fix(es):

  • xorg: xmayland: Use-after-free in XPresentNotify structure creation (CVE-2025-62229)
  • xorg: xwayland: Use-after-free in Xkb client resource removal (CVE-2025-62230)
  • xorg: xmayland: Value overflow in XkbSetCompatMap() (CVE-2025-62231)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2402649 - CVE-2025-62229 xorg: xmayland: Use-after-free in XPresentNotify structure creation
  • BZ - 2402653 - CVE-2025-62230 xorg: xwayland: Use-after-free in Xkb client resource removal
  • BZ - 2402660 - CVE-2025-62231 xorg: xmayland: Value overflow in XkbSetCompatMap()

CVEs

  • CVE-2025-62229
  • CVE-2025-62230
  • CVE-2025-62231

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
tigervnc-1.11.0-8.el8_4.14.src.rpm SHA-256: 78220d605f53b94ada64cd0d349afb84f67f645132cc9203e84c043497211c31
x86_64
tigervnc-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 544a6844844bab1fbdeed4075bf24faf0c89796a32387ad5a1eadfa9f0aa9a10
tigervnc-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 4ff9cef5be56327cf64b7464d69e3336876139f6a1e346d770622d811982aa47
tigervnc-debugsource-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 1451068bb4328615cc66eefbf7cb096f9e7174d8e7fb4287a1ab7428cee42b29
tigervnc-icons-1.11.0-8.el8_4.14.noarch.rpm SHA-256: f18beb6be7e73d347a9762d6c04f67aa93ffc9c723fd500125ec3edac9a96d03
tigervnc-license-1.11.0-8.el8_4.14.noarch.rpm SHA-256: 0fd4d514de0217e8ab397b48d2faecc89e7fb6b36f566f7383423ecd5ecc1a17
tigervnc-selinux-1.11.0-8.el8_4.14.noarch.rpm SHA-256: e8c0369f4e8dcc8f4ee637db588fcda4ba0b6e45ac0b0bdd1ed691eb2b3e324d
tigervnc-server-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 1ad34c8030484082177102650d0d8fe5ec0b01d9eb8f036f1dc45e8d9609e3d6
tigervnc-server-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: a576fdf341df823c7ec0569a9ebcdf60f61538a098549daf8e698ef123f2ebea
tigervnc-server-minimal-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 6dadc8ace7592074fd32aeb94db01913cdaa1f622c8b69e53753f3c40a83b89f
tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: ce0c39e88a9ea4f1ede7fd7069522f9d13891da1d41458d864df0dbd638f9d70
tigervnc-server-module-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: f15ed2da8101327c685874cc22aa50fd6b2e07c8aa512d73ed250330a427c6af
tigervnc-server-module-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 9bfc41d5b6e3ea9ad9173af06740599960842a222ccecc7dc51e227a2935b228

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
tigervnc-1.11.0-8.el8_4.14.src.rpm SHA-256: 78220d605f53b94ada64cd0d349afb84f67f645132cc9203e84c043497211c31
x86_64
tigervnc-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 544a6844844bab1fbdeed4075bf24faf0c89796a32387ad5a1eadfa9f0aa9a10
tigervnc-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 4ff9cef5be56327cf64b7464d69e3336876139f6a1e346d770622d811982aa47
tigervnc-debugsource-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 1451068bb4328615cc66eefbf7cb096f9e7174d8e7fb4287a1ab7428cee42b29
tigervnc-icons-1.11.0-8.el8_4.14.noarch.rpm SHA-256: f18beb6be7e73d347a9762d6c04f67aa93ffc9c723fd500125ec3edac9a96d03
tigervnc-license-1.11.0-8.el8_4.14.noarch.rpm SHA-256: 0fd4d514de0217e8ab397b48d2faecc89e7fb6b36f566f7383423ecd5ecc1a17
tigervnc-selinux-1.11.0-8.el8_4.14.noarch.rpm SHA-256: e8c0369f4e8dcc8f4ee637db588fcda4ba0b6e45ac0b0bdd1ed691eb2b3e324d
tigervnc-server-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 1ad34c8030484082177102650d0d8fe5ec0b01d9eb8f036f1dc45e8d9609e3d6
tigervnc-server-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: a576fdf341df823c7ec0569a9ebcdf60f61538a098549daf8e698ef123f2ebea
tigervnc-server-minimal-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 6dadc8ace7592074fd32aeb94db01913cdaa1f622c8b69e53753f3c40a83b89f
tigervnc-server-minimal-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: ce0c39e88a9ea4f1ede7fd7069522f9d13891da1d41458d864df0dbd638f9d70
tigervnc-server-module-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: f15ed2da8101327c685874cc22aa50fd6b2e07c8aa512d73ed250330a427c6af
tigervnc-server-module-debuginfo-1.11.0-8.el8_4.14.x86_64.rpm SHA-256: 9bfc41d5b6e3ea9ad9173af06740599960842a222ccecc7dc51e227a2935b228

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility