REDHAT-BUG-2486731: Buffer Overflow

Published Jun 9, 2026
·
Updated

GStreamer librfb (RFB/VNC client) heap buffer overflow vulnerability. In rfbdecoder.c (gst-plugins-bad), the rectangle bounds check incorrectly validates area rather than individual dimensions: if (((w h) + (x y)) > (decoder->width decoder->height)). A malicious VNC server can send a FramebufferUpdate with crafted x/y/w/h values (e.g., x=0, y=0, w=2000, h=1 on a 1920-wide framebuffer) that pass this check but extend beyond the framebuffer. The raw encoding function then performs memcpy(frame, p, rawlinesize) where rawlinesize = w bytespp is larger than the framebuffer line, writing past the end of each line into adjacent heap memory. This results in a controlled out-of-bounds heap write. Upstream confirmed by maintainer Sebastian Dröge (2026-06-02): "Confirmed, OOB write. Triggers when connecting to a malicious/broken VNC/RFB server." Fix planned for GStreamer 1.28.4. Upstream issue: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/workitems/5105 (confidential). Reported via PSIRTSUPT-17026 by JUNYI LIU / Moss (moss80199).

Affected Software

1 affected component
GStreamer gst-plugins-bad (librfb)<1.28.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GStreamer librfb (gst-plugins-bad) rfbdecoder.c to a version that resolves this vulnerability.

    Fixed in 1.28.4Patch PSIRTSUPT-17026
  2. Compensating control

    Avoid connecting the GStreamer librfb (RFB/VNC client) to untrusted or potentially malicious VNC/RFB servers; only connect to trusted endpoints to prevent triggering the crafted FramebufferUpdate OOB write.

Event History

Jun 9, 2026
Data Sourced
via Red Hat·07:33 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is REDHAT-BUG-2486731?

REDHAT-BUG-2486731 is a high-severity heap buffer overflow vulnerability in the GStreamer librfb (RFB/VNC client) related to incorrect rectangle bounds checking.

2

What is the severity of REDHAT-BUG-2486731?

The severity of REDHAT-BUG-2486731 is classified as high, with a risk score of 7.

3

How do I fix REDHAT-BUG-2486731?

To fix REDHAT-BUG-2486731, you should update to the latest version of GStreamer gst-plugins-bad where this vulnerability has been addressed.

4

What causes the vulnerability in REDHAT-BUG-2486731?

The vulnerability in REDHAT-BUG-2486731 is caused by a heap buffer overflow due to incorrect validation of area rather than individual dimensions in the rectangle bounds check.

5

What can a malicious VNC server do in relation to REDHAT-BUG-2486731?

A malicious VNC server can exploit REDHAT-BUG-2486731 to send crafted data causing a buffer overflow, potentially leading to arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203