PT-2026-56783 · Gstreamer+1 · Gstreamer+1
CVE-2026-59691
·
Published
2026-07-08
·
Updated
2026-09-02
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
GStreamer (affected versions not specified)
Description
A heap buffer overflow exists in the
rfbsrc plugin. The issue occurs when a client connects to a malicious RFB/VNC server that advertises a 16bpp (bits per pixel) framebuffer and sends Hextile-encoded updates. The Hextile background fill path incorrectly writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch results in an out-of-bounds heap write, which can lead to memory corruption or a denial of service via a process crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gstreamer
Rocky Linux