yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2020-29260
Component Overview
Vulnerability Overview
Name
CVE-2020-29260
Source
NVD (
link
)
Debian (
link
)
Description
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().
CWEs
CWE-400
Published Date
Sep 2, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/LibVNC/libvncserver/commit/bef41f6ec4097a8ee094f90a1b34a708fbd757ec
Patch
https://lists.debian.org/debian-lts-announce/2022/09/msg00035.html
Mailing List
https://github.com/LibVNC/libvncserver/commit/bef41f6ec4097a8ee094f90a1b34a708fbd757ec
Patch
https://lists.debian.org/debian-lts-announce/2022/09/msg00035.html
Mailing List
Analysis
#
Affected Component
Analysis
libvncserver
Patched
Vulnerability Rating
#
7.5
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
libvncserver
buildroot
2025.02.x
0.9.14
Not Affected
libvncserver
buildroot
master
0.9.15
Not Affected
libvncserver
yocto
master
0.9.15
Not Affected
libvncserver
yocto
scarthgap
0.9.14
Not Affected
Resolved with patches
#
libvncserver (yocto:kirkstone)
#
Title
Author
Resolve
1
libvncclient: free vncRec memory in rfbClientCleanup()
Christian Beier <info@christianbeier.net>
CVE-2020-29260