Heap Buffer Overflow in GStreamer's RFB/VNC Client
CVE-2026-52720
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-52720?
A vulnerability exists within GStreamer's librfb (RFB/VNC client) that causes a heap buffer overflow due to improper validation of rectangle bounds. This flaw allows a malicious VNC server to exploit the incorrect bounds check, which only validates the overall area and not the individual dimensions. An attacker could trick a user into connecting to a compromised VNC server, potentially leading to out-of-bounds heap writes. Such exploitation could result in unauthorized code execution or cause the application to crash, necessitating immediate attention and patching.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.4
Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.24.11-3.el10_0.4
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.10.4-6.el7_9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved