Описание
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
Отчет
This is an Important heap buffer overflow vulnerability in GStreamer's librfb RFB/VNC client (gst-plugins-bad). The flaw allows a controlled out-of-bounds heap write when connecting to a malicious VNC server due to an incorrect bounds check that validates rectangle area instead of individual dimensions. The impact affects availability (crash), integrity, and potentially confidentiality, as the controlled heap overflow could be leveraged for code execution. Red Hat products utilizing GStreamer for multimedia processing are affected if they include the rfbsrc element for VNC/RFB screen capture pipelines.
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | gstreamer-plugins-bad-free | Out of support scope | ||
| Red Hat Enterprise Linux 7 | gstreamer-plugins-bad-free | Affected | ||
| Red Hat Enterprise Linux 10 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:36749 | 08.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47717 | 29.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47176 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:37130 | 09.07.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47076 | 28.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47076 | 28.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47075 | 28.07.2026 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | gstreamer1-plugins-bad-free | Fixed | RHSA-2026:47075 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
A heap buffer overflow vulnerability was found in GStreamer's librfb ( ...
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
EPSS
8.8 High
CVSS3