CVE-2026-32853: LibVNCServer UltraZip Encoding Heap Out-of-bounds Read
LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application crash. Attackers can exploit improper bounds checking in the HandleUltraZipBPP() function by manipulating subrectangle header counts to read beyond the allocated heap buffer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LibVNCServer UltraZip encoding handler (HandleUltraZipBPP)to a version that resolves this vulnerability.Fixed in 0.9.15Patch 009008e
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32853?
The severity of CVE-2026-32853 is considered high due to the potential for information disclosure and application crashes.
How do I fix CVE-2026-32853?
To fix CVE-2026-32853, update LibVNCServer to version 0.9.16 or later, where the vulnerability has been mitigated.
What causes CVE-2026-32853?
CVE-2026-32853 is caused by a heap out-of-bounds read vulnerability in the UltraZip encoding handler of LibVNCServer.
Who is affected by CVE-2026-32853?
CVE-2026-32853 affects users of LibVNCServer versions 0.9.15 and earlier.
What are the potential impacts of CVE-2026-32853?
The potential impacts of CVE-2026-32853 include information leakage and unexpected application crashes.