In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade RHEL:9 tigervnc-server-module to version 0:1.12.0-14.el9_2.10 or higher.
This issue was patched in RHSA-2025:2874.
Note: Versions mentioned in the description apply only to the upstream tigervnc-server-module package and not the tigervnc-server-module package as distributed by RHEL.
See How to fix? for RHEL:9 relevant fixed versions and status.
A use-after-free flaw was found in X.Org and Xwayland. When a device is removed while still frozen, the events queued for that device remain while the device is freed. Replaying the events will cause a use-after-free.