-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 12:21:21 +0200 Source: libvncserver Binary: libvncclient1 libvncclient1-dbgsym libvncserver-dev libvncserver1 libvncserver1-dbgsym Architecture: amd64 Version: 0.9.15+dfsg-1+deb13u2 Distribution: trixie Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Sven Geuer Description: libvncclient1 - API to write one's own VNC server - client library libvncserver-dev - API to write one's own VNC server - development files libvncserver1 - API to write one's own VNC server Closes: 1138174 1138253 Changes: libvncserver (0.9.15+dfsg-1+deb13u2) trixie; urgency=medium . * Team upload. * debian/patches: + CVE-2026-44988: Add 0003_CVE-2026-44988.patch fixing Tight gradient decoding overflow (Closes: #1138174). + CVE-2026-50538: Add 0004_CVE-2026-50538.patch fixing attacker-controlled heap out-of-bounds write (Closes: #1138253). Checksums-Sha1: 573543a2b24f6854dae30971ea6ce7b09bb909ae 185492 libvncclient1-dbgsym_0.9.15+dfsg-1+deb13u2_amd64.deb d774fe174f0604cc1177767317075d7c7b12c0cf 197004 libvncclient1_0.9.15+dfsg-1+deb13u2_amd64.deb c6db64a9a93e98751ec5d01a7d7337e4f0ec5c4d 216128 libvncserver-dev_0.9.15+dfsg-1+deb13u2_amd64.deb 0e1479a6f5c06e71182a5fbc0f9b4190710df6fa 354960 libvncserver1-dbgsym_0.9.15+dfsg-1+deb13u2_amd64.deb 7cae571d0d4a8efc30fa8e7816c49dedef4946d3 252872 libvncserver1_0.9.15+dfsg-1+deb13u2_amd64.deb c4ad30cf7e70d40ac588f622e56437a93fe099ed 8844 libvncserver_0.9.15+dfsg-1+deb13u2_amd64-buildd.buildinfo Checksums-Sha256: 1ba767ec7c529585f064990c5578017ce3ac54a3ecda361535367af88cd31a41 185492 libvncclient1-dbgsym_0.9.15+dfsg-1+deb13u2_amd64.deb 13395ab10fb0cffb79e453778b22a26c1faa356fed995a6f25628238a639797a 197004 libvncclient1_0.9.15+dfsg-1+deb13u2_amd64.deb e7f41ea5630eebc9d66100aa63a185640d0120fab39b16cb63f892d7e301b43f 216128 libvncserver-dev_0.9.15+dfsg-1+deb13u2_amd64.deb 30dec92b4b49c220ec48e2b19f3c2b6172c093f4e1cc73db468c72fdffda201a 354960 libvncserver1-dbgsym_0.9.15+dfsg-1+deb13u2_amd64.deb 590a813b679bb3ddb8681aa9b8f3b8ebfe47dd67a499185ad044315199fe56ea 252872 libvncserver1_0.9.15+dfsg-1+deb13u2_amd64.deb dea7eda8a40c82123f70e3f17d2d26b46257989fd68242d41cc811e6d363bc6a 8844 libvncserver_0.9.15+dfsg-1+deb13u2_amd64-buildd.buildinfo Files: 2786ce33f9b8c9e572534dd94a3e1ea4 185492 debug optional libvncclient1-dbgsym_0.9.15+dfsg-1+deb13u2_amd64.deb 7ac304af4ec080bc069acc1210b3f367 197004 libs optional libvncclient1_0.9.15+dfsg-1+deb13u2_amd64.deb 8dcd1cba35d14424ee2be6b2a1e7c19b 216128 libdevel optional libvncserver-dev_0.9.15+dfsg-1+deb13u2_amd64.deb 397d1e129d676c9922b795f2ce2f3903 354960 debug optional libvncserver1-dbgsym_0.9.15+dfsg-1+deb13u2_amd64.deb 71d81ff0bc84a336445a2eaf20975608 252872 libs optional libvncserver1_0.9.15+dfsg-1+deb13u2_amd64.deb 0e9c13697ec950322454201beb4181cc 8844 libs optional libvncserver_0.9.15+dfsg-1+deb13u2_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmpGz+UACgkQN8Ugyu9d QiQaaQ/+OUtKOA7vpSboOufXT76qyFT1h6nkJ9JV6Bz8tCghgt8fULswSw0Srdw4 ZumFV7iKOVvUh7vNMOwm6hPWG4aW8IFDdrqyf1jo/7rOEatg7kVlbI2o21R2+lm4 hGU99wM+2o1Fxy7hg9xL9ubAhRb3Jz1vvwNiiUdGOUWkIZITSCY70+BVCzWaZZ+e vQHKs7kkFLOXggBnRWM7bNdWCs1SS8Z3RN+lyApwD9P00clQr8E3J5cb6lory++3 qaAR9FouYJrj0OdNE34YcZ7+mR4mr3sOPRlWBkHUQx/HcgQGpqmH0PbBndPthNan 3lPnpmxu2PydgZN97gkgDY5tFwvl2ivuPot2/AXYSk0KIMlNcCuGdjeSs6Zor6PO +gub7eCpJ8045Vu5kknZgW7m33ZdiX5aYYOWL5VmUdOjMMQQCQ4ahN0NMNpBmQmO HLyU0v2ogZ6QxR/rAma9WprAhlZ87OBIpCXwVC+gDv214Q0HqbEFM8GkaCT6yzyZ AxcdzpBGpiP8kSGQlFgX+0qghsf2pz6ORaHxSHjK3EhfwG3Q+muQOrqlroDArkfk Uen1I4W4DeltH0Yr04pI1dbMRP+I42A1CrVkH4pLhA5G2HVJ+DHbbRTrseXQIiUU g1uBHU8G8hAlMNdNoDUiNYD7UEP+VV5tnUTQWWcwdTVce5fkN1Q= =iQZw -----END PGP SIGNATURE-----