-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 12:51:14 +0200 Source: libvncserver Binary: libvncclient1 libvncclient1-dbgsym libvncserver-dev libvncserver1 libvncserver1-dbgsym Architecture: amd64 Version: 0.9.14+dfsg-1+deb12u2 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Sven Geuer Description: libvncclient1 - API to write one's own VNC server - client library libvncserver-dev - API to write one's own VNC server - development files libvncserver1 - API to write one's own VNC server Closes: 1138174 1138253 Changes: libvncserver (0.9.14+dfsg-1+deb12u2) bookworm; urgency=medium . * Team upload. * debian/patches: + CVE-2026-44988: Add 0003_CVE-2026-44988.patch fixing Tight gradient decoding overflow (Closes: #1138174). + CVE-2026-50538: Add 0004_CVE-2026-50538.patch fixing attacker-controlled heap out-of-bounds write (Closes: #1138253). Checksums-Sha1: 39d9e8860238e8e23fd80aa8c705b89e11e47746 178464 libvncclient1-dbgsym_0.9.14+dfsg-1+deb12u2_amd64.deb 2218ca5093b0277a0378f744d616da8fe3e0daee 186104 libvncclient1_0.9.14+dfsg-1+deb12u2_amd64.deb e51cd3def4e01bd5b8c506e0776de6e7c62b0dcb 195412 libvncserver-dev_0.9.14+dfsg-1+deb12u2_amd64.deb bf490d1168277922855ef5d3a1c59aa97e703d16 346464 libvncserver1-dbgsym_0.9.14+dfsg-1+deb12u2_amd64.deb 69435f889c64208ceb1bc16095b0158f2412beb9 242204 libvncserver1_0.9.14+dfsg-1+deb12u2_amd64.deb c4dd5aa9cf8430e66d6defd79ccf62883ebd4e9e 8917 libvncserver_0.9.14+dfsg-1+deb12u2_amd64-buildd.buildinfo Checksums-Sha256: 40faf5df6752918cfde0d017489a36c12143dd43f150156f0631b8e2e308a962 178464 libvncclient1-dbgsym_0.9.14+dfsg-1+deb12u2_amd64.deb 1af5703a6f535428f8287600ea35e4b5d4cbe788071cbb09ec556f232a18e77f 186104 libvncclient1_0.9.14+dfsg-1+deb12u2_amd64.deb 7aa739a17878d209a3686caf1e4d095cfe2fe22596d13f9de1815e69243b04de 195412 libvncserver-dev_0.9.14+dfsg-1+deb12u2_amd64.deb be3e0a1738c8d82c45bc2b947e246f581bedac620469f775ee0936042aba5555 346464 libvncserver1-dbgsym_0.9.14+dfsg-1+deb12u2_amd64.deb 9a09b592a8351e4bec19de71a283980ae6fc616f7015075ad1b33d15c560a377 242204 libvncserver1_0.9.14+dfsg-1+deb12u2_amd64.deb e7b7b8b5efd4de16751451e9700f43335c7d1386001eb9a217afe29f8a15b12a 8917 libvncserver_0.9.14+dfsg-1+deb12u2_amd64-buildd.buildinfo Files: 90bf34bdf28e07ad8dc956e70943edce 178464 debug optional libvncclient1-dbgsym_0.9.14+dfsg-1+deb12u2_amd64.deb b98944d63ce3c5043ae0ddc7f5ff957c 186104 libs optional libvncclient1_0.9.14+dfsg-1+deb12u2_amd64.deb c9fc24f374e8147ddd246a14c241e6dd 195412 libdevel optional libvncserver-dev_0.9.14+dfsg-1+deb12u2_amd64.deb 09102c4ffaaa443f1575443ab6b4b9d5 346464 debug optional libvncserver1-dbgsym_0.9.14+dfsg-1+deb12u2_amd64.deb d2947f1f2196549f6c1efc8090db3ff3 242204 libs optional libvncserver1_0.9.14+dfsg-1+deb12u2_amd64.deb 2d60054e5a93a79e6f2c4c2dce3cf597 8917 libs optional libvncserver_0.9.14+dfsg-1+deb12u2_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmpGz5AACgkQN8Ugyu9d QiTkdA//fZSpdUMCcNlfk4Q0XnxAGX0anyg9JQjHtQld9JHcjZMgewkv2fRxkpTd Py8l7dWBxjnAcbcFUe+7KTXHe9qcR1w2d3CPb+1J4NmCesumwJukYNNllULYYEtf VqF995uoayKn9nTSgaB6cok6ExR520SGtFE77aN9wh8+o5kvqMrTnrSVpQ79MTP9 i2Iq7b6paOuWIdzEVN6dhw8bl30Z00BZ92zm1FBRemJ4mUvN6Od8ps73Vf1+VKo2 aiylDgZ/GeomYt7gTRXR7lnJkK5kZKLbvG4AJmz5GjK9eVZiNu2dGxpe2GrNK+G0 48SUprbxs34ew53AWCz5z3EVxQ/XTjUvKzxDu97/zILY4czrwGzCrQ2Gmz9WYnEx yNF20AiGhocgCaC2pwLmwDHzWvdBBVemWkfj9J3CK2EuCWVNDgByO0LoE8oLy0Gq l4k8Cj0cYKc5l/3sr6LK+3CcWOMsR4V+eJtNoS0sG+505jQrTCz4cGrHCO2oVU1v a52xYrKzjJgNEpEWUJ20omSGEN49UmoMWcWQz2+6i3hFbMC4eLHejQQ2sLANWxkT uOjCr7E+l6GTlQd2N3sSkQ/1GCor1DHtj8eOZ/EC3NZWAgmSapOHS9XrKxUGWisW XpehTceIvXDuv/ZYvDPJU2sQD8hxq5hoU1/8lIjy7L6x/6b8UeM= =XSjv -----END PGP SIGNATURE-----