CVE-2026-52720
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:1.26.7-2.el10_2.4 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:1.24.11-3.el10_0.4 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:1.10.4-6.el7_9 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:0.10.23-25.el7_9 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | 0:1.16.1-8.el8_10 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_4.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | 0:1.16.1-4.el8_4.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:1.16.1-4.el8_6.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | 0:1.16.1-4.el8_6.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:1.16.1-4.el8_8.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:1.16.1-4.el8_8.2 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:1.22.12-7.el9_8.1 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:1.18.4-9.el9_2.3 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | 0:1.22.1-6.el9_4.4 < * | unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:1.22.12-5.el9_6.4 < * | unaffected |
Weaknesses
- CWE-122: Heap-based Buffer Overflow
Workarounds
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
gstreamer1-plugins-bad-free: GStreamer: Heap buffer overflow via crafted VNC server rectangle in librfb
Additional References
- https://access.redhat.com/security/cve/CVE-2026-52720
- https://bugzilla.redhat.com/show_bug.cgi?id=2486731
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52720.json
- https://access.redhat.com/errata/RHSA-2026:49517
- https://access.redhat.com/errata/RHSA-2026:47176
- https://access.redhat.com/errata/RHSA-2026:47717
- https://access.redhat.com/errata/RHSA-2026:36749
- https://access.redhat.com/errata/RHSA-2026:37130
- https://access.redhat.com/errata/RHSA-2026:47076
- https://access.redhat.com/errata/RHSA-2026:47075
- https://access.redhat.com/errata/RHSA-2026:47718
- https://access.redhat.com/errata/RHSA-2026:47069
- https://access.redhat.com/errata/RHSA-2026:47071
- https://access.redhat.com/errata/RHSA-2026:47070
- https://access.redhat.com/errata/RHSA-2026:36834
References
- https://access.redhat.com/errata/RHSA-2026:36749
- https://access.redhat.com/errata/RHSA-2026:36834
- https://access.redhat.com/errata/RHSA-2026:37130
- https://access.redhat.com/errata/RHSA-2026:47069
- https://access.redhat.com/errata/RHSA-2026:47070
- https://access.redhat.com/errata/RHSA-2026:47071
- https://access.redhat.com/errata/RHSA-2026:47075
- https://access.redhat.com/errata/RHSA-2026:47076
- https://access.redhat.com/errata/RHSA-2026:47176
- https://access.redhat.com/errata/RHSA-2026:47717
- https://access.redhat.com/errata/RHSA-2026:47718
- https://access.redhat.com/errata/RHSA-2026:49517
- https://access.redhat.com/security/cve/CVE-2026-52720
- https://bugzilla.redhat.com/show_bug.cgi?id=2486731
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5105
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.