PT-2026-52181 · Unknown+2 · Libvncserver+3
CVE-2026-50538
·
Published
2026-06-15
·
Updated
2026-09-02
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibVNCClient versions 0.9.12 through 0.9.15
Description
A malicious or man-in-the-middle VNC server can force a connecting client to perform an out-of-bounds heap write, which occurs when data is written beyond the allocated memory boundary of the framebuffer. This issue resides in the Tight decoder, a method used to compress VNC data to reduce bandwidth. The attacker can control the length, contents, and offset of the write without requiring authentication. This can lead to an unconditional crash resulting in a denial of service or the overwriting of an application callback pointer to redirect execution to attacker-chosen code.
Recommendations
Update LibVNCClient to a version that includes commit 540332be3e0acc566fa64da6f1b4680c72c724dd.
Update libvncclient1, libvncserver-dev, and libvncserver1 to version 0.9.14+dfsg-1ubuntu0.2.
Exploit
Fix
DoS
Memory Corruption
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libvncserver
Linuxmint
Ubuntu
Libvncclient