Heap Buffer Overflow in GStreamer’s rfbsrc Plugin Exposes Vulnerability
CVE-2026-59691
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 9 July 2026
What is CVE-2026-59691?
GStreamer’s rfbsrc plugin exhibits a vulnerability caused by a heap buffer overflow. This issue arises when a client connects to an untrusted RFB/VNC server that improperly advertises a 16bpp framebuffer. If the server sends Hextile-encoded updates, the processing of the Hextile background fill can lead to a scenario where 32-bit pixel values are incorrectly written into a buffer that is allocated for only 16-bit pixels. This mismatch results in an out-of-bounds heap write, which may lead to a denial of service, characterized by unexpected process crashes, as well as potential memory corruption.
Affected Version(s)
Red Hat Enterprise Linux 10 0:1.26.7-2.el10_2.6
Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.24.11-3.el10_0.6
Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:1.10.4-7.el7_9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved