Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-52720

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

Отчет

This is an Important heap buffer overflow vulnerability in GStreamer's librfb RFB/VNC client (gst-plugins-bad). The flaw allows a controlled out-of-bounds heap write when connecting to a malicious VNC server due to an incorrect bounds check that validates rectangle area instead of individual dimensions. The impact affects availability (crash), integrity, and potentially confidentiality, as the controlled heap overflow could be leveraged for code execution. Red Hat products utilizing GStreamer for multimedia processing are affected if they include the rfbsrc element for VNC/RFB screen capture pipelines.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeOut of support scope
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeAffected
Red Hat Enterprise Linux 10gstreamer1-plugins-bad-freeFixedRHSA-2026:3674908.07.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4771729.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4717628.07.2026
Red Hat Enterprise Linux 8gstreamer1-plugins-bad-freeFixedRHSA-2026:3713009.07.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4707628.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Ongstreamer1-plugins-bad-freeFixedRHSA-2026:4707628.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportgstreamer1-plugins-bad-freeFixedRHSA-2026:4707528.07.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-Ongstreamer1-plugins-bad-freeFixedRHSA-2026:4707528.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2486731gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb

EPSS

Процентиль: 47%
0.00638
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
nvd
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

CVSS3: 8.8
debian
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb ( ...

CVSS3: 8.8
github
около 2 месяцев назад

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.

rocky
21 день назад

Important: gstreamer1-plugins-bad-free security update

EPSS

Процентиль: 47%
0.00638
Низкий

8.8 High

CVSS3