PT-2026-56783 · Gstreamer+1 · Gstreamer+1

CVE-2026-59691

·

Published

2026-07-08

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions GStreamer (affected versions not specified)
Description A heap buffer overflow exists in the rfbsrc plugin. The issue occurs when a client connects to a malicious RFB/VNC server that advertises a 16bpp (bits per pixel) framebuffer and sends Hextile-encoded updates. The Hextile background fill path incorrectly writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch results in an out-of-bounds heap write, which can lead to memory corruption or a denial of service via a process crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47179
ALSA-2026:47180
ALSA-2026:47731
CVE-2026-59691
ECHO-AE12-BA77-0223
RHSA-2026:47179
RHSA-2026:47180
RHSA-2026:47731
RHSA-2026:54658
RHSA-2026:54659
RHSA-2026:54660
RHSA-2026:54664
RHSA-2026:54665
RHSA-2026:54752
RHSA-2026:56658
RHSA-2026:56772
RHSA-2026:62532

Affected Products

Gstreamer
Rocky Linux