Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:46385 - Security Advisory
Issued:
2026-07-27
Updated:
2026-07-27

RHSA-2026:46385 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: tigervnc security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for tigervnc is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Virtual Network Computing (VNC) is a remote display system which allows users to view a computing desktop environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. TigerVNC is a suite of VNC servers and clients.

Security Fix(es):

  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch (CVE-2026-50256)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence() (CVE-2026-50257)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels (CVE-2026-50258)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing (CVE-2026-50259)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter() (CVE-2026-50260)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter() (CVE-2026-50261)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes (CVE-2026-50262)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow() (CVE-2026-50263)
  • xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat (CVE-2026-50264)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2485380 - CVE-2026-50256 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libXfont2 name length mismatch
  • BZ - 2485382 - CVE-2026-50257 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in miSyncDestroyFence()
  • BZ - 2485383 - CVE-2026-50258 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB key types due to unchecked shift levels
  • BZ - 2485384 - CVE-2026-50259 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: stack buffer overflow in XKB SetMap request via mapWidths indexing
  • BZ - 2485385 - CVE-2026-50260 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in FreeCounter()
  • BZ - 2485386 - CVE-2026-50261 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free in SyncChangeCounter()
  • BZ - 2485387 - CVE-2026-50262 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds read/write in GLX ChangeDrawableAttributes
  • BZ - 2485388 - CVE-2026-50263 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: use-after-free information disclosure in CreateSaverWindow()
  • BZ - 2485389 - CVE-2026-50264 xorg-x11-server: xorg-x11-server-Xwayland: xorg-x11-server: out-of-bounds heap write in DRI2 DRIGetBuffers/DRIGetBuffersWithFormat

CVEs

  • CVE-2026-50256
  • CVE-2026-50257
  • CVE-2026-50258
  • CVE-2026-50259
  • CVE-2026-50260
  • CVE-2026-50261
  • CVE-2026-50262
  • CVE-2026-50263
  • CVE-2026-50264

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8

SRPM
tigervnc-1.12.0-15.el8_8.18.src.rpm SHA-256: eeee51266b07310f8d2d74bdc51e34ca0cc6e2399fec6c165b79adfa3d8bb035
x86_64
tigervnc-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: f7dab082d10a92560f1a8dd62eb834e745fb54602b26367f77307a5104e931ac
tigervnc-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 2a38a618baee3101cc9c4c681670e6ed11734e1813f56b2dfddfd85ac9f6aec7
tigervnc-debugsource-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 6268a54ad379c06805b23f0b10cf0fdb3de1b892e402f85ba499dbbf97b9eca5
tigervnc-icons-1.12.0-15.el8_8.18.noarch.rpm SHA-256: 5b6c0774acda80fde2fafcd2d001998a38cb66c7b879eeeae0b01973f2a9971f
tigervnc-license-1.12.0-15.el8_8.18.noarch.rpm SHA-256: a6c21d54ef3bad861949df9fe76fab6290845ee89c8bff6d9c6cb5a047d0a749
tigervnc-selinux-1.12.0-15.el8_8.18.noarch.rpm SHA-256: aa3111fe5058445e516c265ff5e1f22b86c66c3ca8419a673c827508624e47fa
tigervnc-server-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 21a68f8f151bdd9e1b9e5b65167a14de082c4c971a2c8b9e9f81851130e223ac
tigervnc-server-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: f7093764b4ac8ccc5a6c09517ef88422789851c8185205ff0ade5c292435d1f0
tigervnc-server-minimal-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 0f11aa310c27098fb3dcba5b0befeb133926cc7971247e1fc4dcf217c706ded8
tigervnc-server-minimal-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 2b327679126efe9e41c7788baa87256a8ecd6ac2e7a3dcaaa40e51e4892a8018
tigervnc-server-module-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: a5311b9e4b7faf286f82151d7da91cf7b389d6c380175df92da8bd83ef8f92d7
tigervnc-server-module-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 249bccaf3a8ca78eb39e0e179cf3f783d2132603d5352668e08aa17cb40ffb18

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
tigervnc-1.12.0-15.el8_8.18.src.rpm SHA-256: eeee51266b07310f8d2d74bdc51e34ca0cc6e2399fec6c165b79adfa3d8bb035
x86_64
tigervnc-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: f7dab082d10a92560f1a8dd62eb834e745fb54602b26367f77307a5104e931ac
tigervnc-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 2a38a618baee3101cc9c4c681670e6ed11734e1813f56b2dfddfd85ac9f6aec7
tigervnc-debugsource-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 6268a54ad379c06805b23f0b10cf0fdb3de1b892e402f85ba499dbbf97b9eca5
tigervnc-icons-1.12.0-15.el8_8.18.noarch.rpm SHA-256: 5b6c0774acda80fde2fafcd2d001998a38cb66c7b879eeeae0b01973f2a9971f
tigervnc-license-1.12.0-15.el8_8.18.noarch.rpm SHA-256: a6c21d54ef3bad861949df9fe76fab6290845ee89c8bff6d9c6cb5a047d0a749
tigervnc-selinux-1.12.0-15.el8_8.18.noarch.rpm SHA-256: aa3111fe5058445e516c265ff5e1f22b86c66c3ca8419a673c827508624e47fa
tigervnc-server-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 21a68f8f151bdd9e1b9e5b65167a14de082c4c971a2c8b9e9f81851130e223ac
tigervnc-server-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: f7093764b4ac8ccc5a6c09517ef88422789851c8185205ff0ade5c292435d1f0
tigervnc-server-minimal-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 0f11aa310c27098fb3dcba5b0befeb133926cc7971247e1fc4dcf217c706ded8
tigervnc-server-minimal-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 2b327679126efe9e41c7788baa87256a8ecd6ac2e7a3dcaaa40e51e4892a8018
tigervnc-server-module-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: a5311b9e4b7faf286f82151d7da91cf7b389d6c380175df92da8bd83ef8f92d7
tigervnc-server-module-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 249bccaf3a8ca78eb39e0e179cf3f783d2132603d5352668e08aa17cb40ffb18

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
tigervnc-1.12.0-15.el8_8.18.src.rpm SHA-256: eeee51266b07310f8d2d74bdc51e34ca0cc6e2399fec6c165b79adfa3d8bb035
ppc64le
tigervnc-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: 920b992dbe61b15191e592ab57185b5a7302a87af87aabeb7c2a9db62700bdf4
tigervnc-debuginfo-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: c45efde13bc417447cc5874cdf3d480fff6355c325bc74aed292a2734d1471e7
tigervnc-debugsource-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: d13632b2cc49c94cab52bdb2206902b116d4ffef91cbb27715e91e511ad25517
tigervnc-icons-1.12.0-15.el8_8.18.noarch.rpm SHA-256: 5b6c0774acda80fde2fafcd2d001998a38cb66c7b879eeeae0b01973f2a9971f
tigervnc-license-1.12.0-15.el8_8.18.noarch.rpm SHA-256: a6c21d54ef3bad861949df9fe76fab6290845ee89c8bff6d9c6cb5a047d0a749
tigervnc-selinux-1.12.0-15.el8_8.18.noarch.rpm SHA-256: aa3111fe5058445e516c265ff5e1f22b86c66c3ca8419a673c827508624e47fa
tigervnc-server-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: d9dcb13fe35514a8b3b3009473d2c810e0d8ce888318cf11269d0ee63ca0b081
tigervnc-server-debuginfo-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: 83555cdaa257d57f9578ac3f8bc1f8cfeddeffab2e638562c4b3abc7eb2dd29e
tigervnc-server-minimal-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: 40810b8c8b893751f52fced4b614b9aebd2732b7c7c3ded422c09ea77d54cbbd
tigervnc-server-minimal-debuginfo-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: fda541459cf8fff095d1e2948f1bb3176794187dbfb6ec3347295fcdf175e20d
tigervnc-server-module-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: b7ea58dd09e0b65746c81f56c94dbfa8969cef76a0d1ce283509d654cef6644d
tigervnc-server-module-debuginfo-1.12.0-15.el8_8.18.ppc64le.rpm SHA-256: 9e8080554f25660a53f9bcc7fcd6b3471a4e9f1366e10992dd4e71f7554d1100

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
tigervnc-1.12.0-15.el8_8.18.src.rpm SHA-256: eeee51266b07310f8d2d74bdc51e34ca0cc6e2399fec6c165b79adfa3d8bb035
x86_64
tigervnc-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: f7dab082d10a92560f1a8dd62eb834e745fb54602b26367f77307a5104e931ac
tigervnc-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 2a38a618baee3101cc9c4c681670e6ed11734e1813f56b2dfddfd85ac9f6aec7
tigervnc-debugsource-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 6268a54ad379c06805b23f0b10cf0fdb3de1b892e402f85ba499dbbf97b9eca5
tigervnc-icons-1.12.0-15.el8_8.18.noarch.rpm SHA-256: 5b6c0774acda80fde2fafcd2d001998a38cb66c7b879eeeae0b01973f2a9971f
tigervnc-license-1.12.0-15.el8_8.18.noarch.rpm SHA-256: a6c21d54ef3bad861949df9fe76fab6290845ee89c8bff6d9c6cb5a047d0a749
tigervnc-selinux-1.12.0-15.el8_8.18.noarch.rpm SHA-256: aa3111fe5058445e516c265ff5e1f22b86c66c3ca8419a673c827508624e47fa
tigervnc-server-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 21a68f8f151bdd9e1b9e5b65167a14de082c4c971a2c8b9e9f81851130e223ac
tigervnc-server-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: f7093764b4ac8ccc5a6c09517ef88422789851c8185205ff0ade5c292435d1f0
tigervnc-server-minimal-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 0f11aa310c27098fb3dcba5b0befeb133926cc7971247e1fc4dcf217c706ded8
tigervnc-server-minimal-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 2b327679126efe9e41c7788baa87256a8ecd6ac2e7a3dcaaa40e51e4892a8018
tigervnc-server-module-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: a5311b9e4b7faf286f82151d7da91cf7b389d6c380175df92da8bd83ef8f92d7
tigervnc-server-module-debuginfo-1.12.0-15.el8_8.18.x86_64.rpm SHA-256: 249bccaf3a8ca78eb39e0e179cf3f783d2132603d5352668e08aa17cb40ffb18

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility