🛡️ USN-8463-1 — libvncserver
Description
libvncserver vulnerabilities
It was discovered that LibVNCServer had a memory leak in the client cleanup
function. An attacker could possibly use this issue to cause LibVNCServer
to consume memory, leading to a denial of service. This issue only affected
Ubuntu 22.04 LTS. (CVE-2020-29260)
It was discovered that LibVNCServer did not properly validate bounds when
handling UltraZip encoding subrectangles. A remote attacker could possibly
use this issue to obtain sensitive information or cause a denial of
service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 25.04. (CVE-2026-32853)
It was discovered that LibVNCServer did not properly validate return values
in the HTTP proxy handlers. A remote attacker could possibly use this issue
to cause LibVNCServer to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2026-32854)
It was discovered that LibVNCServer did not properly handle Tight encoding
gradient filter rectangles. A remote attacker could use this issue to cause
LibVNCServer to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-44988)
Affected software
USN-8463-1 is recorded against 1 package.
- libvncserver (fixed in 0.9.15+dfsg-3ubuntu0.1)
Timeline and source
Published on 23 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| libvncserver | — | 0.9.15+dfsg-3ubuntu0.1 |
References
Similar Threats
- Unknown MGASA-2026-0315
- Unknown DEBIAN-CVE-2026-50538
- High OESA-2026-2564
- High OESA-2026-2565
- High OESA-2026-2490
More USN 8 advisories
Browse all of USN 8 in the advisory index.
Free Vulnerability Check
Is your site affected by USN-8463-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-8463-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.