Out-of-Bounds Heap Write in LibVNCClient Library by LibVNC
CVE-2026-50538
8.8HIGH
What is CVE-2026-50538?
LibVNCClient versions 0.9.12 through 0.9.15 are vulnerable to an out-of-bounds heap write, which can be exploited by a malicious VNC server. This vulnerability allows the attacker to control the length, contents, and offset of the data being written. Without the need for authentication, an attacker can initiate the exploit through a single FramebufferUpdate as soon as the victim connects. This can lead to a denial-of-service condition by crashing the client and creates a risk for arbitrary code execution if an application callback pointer is overwritten. Patching for this issue is available in commit 540332be3e0acc566fa64da6f1b4680c72c724dd.
Affected Version(s)
libvncserver >= 0.9.12, <= 0.9.15
