CVE-2026-34352

Name
CVE-2026-34352
Description
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/TigerVNC/tigervnc/commit/0b5cab169d847789efa54459a87659d3fd484393
cve@mitre.org https://groups.google.com/g/tigervnc-announce/c/anHL9WLshLI
cve@mitre.org https://sourceforge.net/projects/tigervnc/files/stable/1.16.2
cve@mitre.org https://www.openwall.com/lists/oss-security/2026/03/26/7

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:tigervnc:tigervnc:*:*:*:*:*:*:*:* tigervnc >= None < 1.16.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
tigervnc edge-community 1.15.0-r2 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
tigervnc edge-community 1.15.0-r1 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
tigervnc edge-community 1.15.0-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
tigervnc edge-community 1.13.1-r5 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
tigervnc 3.23-community 1.15.0-r2 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable