PT-2026-49336 · Gstreamer+1 · Gstreamer+1

·

CVE-2026-52720

·

Published

2026-06-15

·

Updated

2026-08-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GStreamer (affected versions not specified)
Description A heap buffer overflow exists in the librfb (RFB/VNC client) component of GStreamer. The issue occurs because the rectangle bounds check validates the total area instead of individual dimensions. This allows a malicious VNC server to send a rectangle that extends beyond the framebuffer, leading to an out-of-bounds heap write. A remote attacker could exploit this by tricking a user into connecting to a malicious VNC server, potentially resulting in code execution or a system crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36749
ALSA-2026:36834
ALSA-2026:37130
CVE-2026-52720
ECHO-08DB-101F-0369
OPENSUSE-SU-2026:11088-1
OPENSUSE-SU-2026:21370-1
RHSA-2026:37130
RHSA-2026:47075
RHSA-2026:47076
RHSA-2026:47176
RHSA-2026:47718
RHSA-2026:49517
SUSE-SU-2026:22752-1
SUSE-SU-2026:22817-1
SUSE-SU-2026:3058-1
SUSE-SU-2026:3125-1
SUSE-SU-2026:3133-1
SUSE-SU-2026:3299-1

Affected Products

Gstreamer
Rocky Linux