PT-2026-52181 · Unknown+2 · Libvncserver+3

CVE-2026-50538

·

Published

2026-06-15

·

Updated

2026-09-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibVNCClient versions 0.9.12 through 0.9.15
Description A malicious or man-in-the-middle VNC server can force a connecting client to perform an out-of-bounds heap write, which occurs when data is written beyond the allocated memory boundary of the framebuffer. This issue resides in the Tight decoder, a method used to compress VNC data to reduce bandwidth. The attacker can control the length, contents, and offset of the write without requiring authentication. This can lead to an unconditional crash resulting in a denial of service or the overwriting of an application callback pointer to redirect execution to attacker-chosen code.
Recommendations Update LibVNCClient to a version that includes commit 540332be3e0acc566fa64da6f1b4680c72c724dd. Update libvncclient1, libvncserver-dev, and libvncserver1 to version 0.9.14+dfsg-1ubuntu0.2.

Exploit

Fix

DoS

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50538
GHSA-V9PM-47H4-JCQ8
OESA-2026-3318
OESA-2026-3319
OESA-2026-3320
OESA-2026-3489
OPENSUSE-SU-2026:11601-1
OPENSUSE-SU-2026:21735-1
SUSE-SU-2026:3803-1
USN-8494-1

Affected Products

Libvncserver
Linuxmint
Ubuntu
Libvncclient