-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Jun 2026 12:51:14 +0200 Source: libvncserver Binary: libvncclient1 libvncclient1-dbgsym libvncserver-dev libvncserver1 libvncserver1-dbgsym Architecture: armhf Version: 0.9.14+dfsg-1+deb12u2 Distribution: bookworm Urgency: medium Maintainer: armhf Build Daemon (arm-conova-01) Changed-By: Sven Geuer Description: libvncclient1 - API to write one's own VNC server - client library libvncserver-dev - API to write one's own VNC server - development files libvncserver1 - API to write one's own VNC server Closes: 1138174 1138253 Changes: libvncserver (0.9.14+dfsg-1+deb12u2) bookworm; urgency=medium . * Team upload. * debian/patches: + CVE-2026-44988: Add 0003_CVE-2026-44988.patch fixing Tight gradient decoding overflow (Closes: #1138174). + CVE-2026-50538: Add 0004_CVE-2026-50538.patch fixing attacker-controlled heap out-of-bounds write (Closes: #1138253). Checksums-Sha1: bfbcd0113661851198961ea134e5c29844eeeea4 172240 libvncclient1-dbgsym_0.9.14+dfsg-1+deb12u2_armhf.deb 9535f6847e313cc673820943ebff0b0785f55afa 176740 libvncclient1_0.9.14+dfsg-1+deb12u2_armhf.deb 923769948a718ccbc4f038f90f9c39473adfe661 195412 libvncserver-dev_0.9.14+dfsg-1+deb12u2_armhf.deb b606c5f5b3cec65f1b9ca576bd5e180d446650be 339160 libvncserver1-dbgsym_0.9.14+dfsg-1+deb12u2_armhf.deb 8a5f2a9b50b540b8400d8e5f71b283ed295ed25c 224408 libvncserver1_0.9.14+dfsg-1+deb12u2_armhf.deb aa54e1b4f4afe54e123b745cd55198b5fecd1b7c 8776 libvncserver_0.9.14+dfsg-1+deb12u2_armhf-buildd.buildinfo Checksums-Sha256: 80e390346dac8550dfde286d355348a5876d42c8a3d41324ae39b1a3e7c84a68 172240 libvncclient1-dbgsym_0.9.14+dfsg-1+deb12u2_armhf.deb b8db95e8d195c0d8a0212dd4e24e43c1154cf91558917fd0b340cb549b85cbc9 176740 libvncclient1_0.9.14+dfsg-1+deb12u2_armhf.deb 719e26026e2947b10d6d1639bfb3f198245f58cf153d6405eb50dbd555ec4066 195412 libvncserver-dev_0.9.14+dfsg-1+deb12u2_armhf.deb 8d4f333a4f9435529fcbaf83711498ae9aa625565af33f388b1465321f994a1c 339160 libvncserver1-dbgsym_0.9.14+dfsg-1+deb12u2_armhf.deb 553a689527004e9c22924f45c9129cab84143f7d576b4e44568f04e86bc78b3d 224408 libvncserver1_0.9.14+dfsg-1+deb12u2_armhf.deb 8000cf94836f216628740412623471620a55bd5c95435ce4135c4715039b5632 8776 libvncserver_0.9.14+dfsg-1+deb12u2_armhf-buildd.buildinfo Files: 728e7e265648b2a1f80b6a519e18ab73 172240 debug optional libvncclient1-dbgsym_0.9.14+dfsg-1+deb12u2_armhf.deb 1b08c994252479b6edfa9f37a634e2ec 176740 libs optional libvncclient1_0.9.14+dfsg-1+deb12u2_armhf.deb 6bdb17d461cc60da903e2c5b408d259e 195412 libdevel optional libvncserver-dev_0.9.14+dfsg-1+deb12u2_armhf.deb 1fbb1c31f500d913042f6abb9a497dbc 339160 debug optional libvncserver1-dbgsym_0.9.14+dfsg-1+deb12u2_armhf.deb d6f3d769c690c084e4a04acbed1c1547 224408 libs optional libvncserver1_0.9.14+dfsg-1+deb12u2_armhf.deb 9cb0f1b3b47e3352110f5cfa75dbcd6a 8776 libs optional libvncserver_0.9.14+dfsg-1+deb12u2_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEO4qAQUSIo2p/kVRf8U6eOZMpj68FAmpGz5cACgkQ8U6eOZMp j6/FTw//TGWib0du0wZiHWo1Ip5+zUHKWUXAQX0W++s4n3btek614Js1T02wGf5v e0H6dxALqr+G2nh4OMUtpt84wDCs28eEy0iNISiAis2rgIT+omsbUWPxPdjUdbS0 yOvIN5Fpgzeyyw18aJ2SGPLNi2t+68XEI82AnYRemYuBGNguFj/Lkjbcf3RAwWem Yh8Hex9XvxxIvY889/jFUonLgWX0i7s0zoJRM4g3ypeXlTsYk2MlaDGxoWm71I9E zN97OB8TkL6LDZslJA3jkhfjlAjCBS4SvXHnwmubmFtSQ03e5VnnwU5CtSXv7q53 Nd7DiyOG2v4hBXbduXNBDgUB/mzM2FxKm/Aq6T5KNRWK3tPSCZivLB1IkvPVPVs6 znkXkH+wui/Cl8E6IanXO3jjc+5upb5Dn1ez2IY2HSnXinDVzocrSkQ/krMEPGCQ c7VWLQAFNNXjot8JmAwNHxTMFBN+QEBR5E9LFqluITJwndeG9v1cpeO70BO0Qr8U 26mTwo1HNFOT4VRz+rZEtxFdzHrRARKQ1BAUnYun0rpobwHOpwxgGbjfj28hcVB7 1/B7LM1jts4rgf9zwS0PuzSYfEdkunYEvbCUS5GqZ196v0kF5usfe4czxfPWU6gb oBP92GI8YCJId5Mp635P4D23kMyJ5DYKRZ6n9ts4QLzxSuuuxJU= =g/u0 -----END PGP SIGNATURE-----