#1136644 neatvnc: CVE-2026-42859

Package:
src:neatvnc
Source:
src:neatvnc
Submitter:
Salvatore Bonaccorso
Date:
2026-07-11 12:09:15 UTC
Severity:
normal
Tags:
#1136644#5
Date:
2026-05-14 10:00:10 UTC
From:
To:
Hi,

The following vulnerability was published for neatvnc.

CVE-2026-42859[0]:
| Neat VNC is a VNC server library. Prior to 0.9.6, a pre-
| authentication stack buffer overflow exists in neatvnc in the RSA-
| AES security type handler. An unauthenticated remote attacker who
| can reach the VNC listening socket can send a crafted security type
| 5 (RSA-AES) or security type 129 (RSA-AES-256) handshake with an
| oversized client RSA public key, causing rsa_aes_send_challenge in
| src/auth/rsa-aes.c to overflow a 1024-byte on-stack buffer when
| encrypting the server challenge. This results in at least a denial
| of service via server crash. This vulnerability is fixed in 0.9.6.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-42859
https://www.cve.org/CVERecord?id=CVE-2026-42859
[1] https://github.com/any1/neatvnc/security/advisories/GHSA-567c-gpv8-qh9h
[2] https://github.com/any1/neatvnc/commit/1f6cd6b75cc167fed3a19a9d1552a1f662f6b337

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1136644#14
Date:
2026-07-06 18:09:12 UTC
From:
To:
Dear maintainer,

I've prepared an NMU for neatvnc (versioned as 0.9.1+dfsg-1.1) and
uploaded it to DELAYED/5. Please feel free to tell me if I should
cancel it.

cu
Adrian

#1136644#23
Date:
2026-07-06 19:15:51 UTC
From:
To:
Hi Adrian,

I am planning to launch the transition for aml/neatvnc tomorrow, and
all relevant preparatory work has been completed.

Thanks,
Han

#1136644#28
Date:
2026-07-11 12:07:55 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
neatvnc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1136644@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Adrian Bunk <bunk@debian.org> (supplier of updated neatvnc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 06 Jul 2026 20:56:40 +0300
Source: neatvnc
Architecture: source
Version: 0.9.1+dfsg-1.1
Distribution: unstable
Urgency: medium
Maintainer: Han Gao <rabenda.cn@gmail.com>
Changed-By: Adrian Bunk <bunk@debian.org>
Closes: 1136644
Changes:
 neatvnc (0.9.1+dfsg-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * CVE-2026-42859: Buffer overflow with oversized RSA public keys
     (Closes: #1136644)
   * auth: vencrypt: Reject excessively long usernames and passwords
Checksums-Sha1:
 be2275bbdbeec7a26ec0f1b1ad798363eef49504 2103 neatvnc_0.9.1+dfsg-1.1.dsc
 6f9e5a04a77fa0479f5808367aa71e0e25867157 13988 neatvnc_0.9.1+dfsg-1.1.debian.tar.xz
Checksums-Sha256:
 49f7ab7f6da4d9e5e527aa462fed472584b0617518acae91c52c4a8742e6c4af 2103 neatvnc_0.9.1+dfsg-1.1.dsc
 255b2f172b417c0c6337fe3e5d9db2b1e032848d02e2e99b8d09496c70b31f8b 13988 neatvnc_0.9.1+dfsg-1.1.debian.tar.xz
Files:
 4b5fa3293cbbc4165bc33881b2568ac0 2103 libs optional neatvnc_0.9.1+dfsg-1.1.dsc
 48df7ca2cb9e09c4b0113cd5e4993811 13988 libs optional neatvnc_0.9.1+dfsg-1.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmpL7w4ACgkQiNJCh6LY
mLG+6BAAqOOMG7hcRj2FoR+l3KYqfXAGxoJdVt4UWKLcHLu0X9AAy1cBU2Kg4ra0
LT8QYF4D82Qua0h8fHp5Ow+wfxwCGD88jjrmtkD4B+V6NYMohVv7Hwv2kMmYOxCw
sYQF5TplLDGs6+QOULQU/aLNtiYWkms2cU6RK5UBRCcVvGNoGxa1PhzLu5v2PEnz
h1L0UrLRZSkRrSz/of5uGpGn7nTce6gIJeH0WCOoEaXFHqzB8yYd55wGmirqrw7c
u9oY/xOCC3s1IkkD/uFhNu57BYvQTxIBjJTOJkjt9582w5KxAKTAIHulHTFb4BkG
f51/wSuRugXvA2Tw5xSRcWzneJFR5UFFqY4r74iAAO/SkK5B9RmLhpvxzATv0Mw1
hizqUrMAwtHH+hM9lOGDX7dCUfQPvwkloC8MTHuQLpGrOD8T4bKmM36tpY0Pk6i+
qImr9zmlXs600Z8cq+Dv8dADl/rmNGyn520WZbGeriTPYuS1s+PHBTbq0PHnBCXK
em+xLoS6k6Bd5vYXukEY36pjB2Hl/NfBqqyZ6rwowRIi+t7kA2qHavJKioydVkCf
f1YsSldczSxNFX3IV6XKrArF1t+NO69hx9HxpYl4ctRv0TXE04+u9UYb+V5bH/XC
c1iw4n35jE5iXpPSrEt5VFJBVc0+WDi4X9oO+2dDomn5JlD2U2A=
=MvQp
-----END PGP SIGNATURE-----