CVE-2026-59691: Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer

Published Jul 6, 2026
·
Updated

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.

Other sources

A heap buffer overflow was found in GStreamer's rfbsrc plugin (gst-plugins-bad, librfb component). In rfbdecoderfillrectangle(), when a malicious RFB/VNC server advertises a 16bpp RGB565 framebuffer and sends a Hextile-encoded update, the background fill path computes the destination offset using decoder->bytespp (2 bytes) but casts the destination to guint32 and writes one 32-bit value per pixel. For bytespp == 2, the framebuffer is allocated as 2 bytes per pixel, but the fill loop writes and advances by 4 bytes per pixel, causing a heap out-of-bounds write.

File: subprojects/gst-plugins-bad/gst/librfb/rfbdecoder.c Function: rfbdecoderfillrectangle()

A remote attacker controlling an RFB/VNC server can trigger this by having a client connect using rfbsrc. The demonstrated impact is heap-buffer-overflow and process abort. Since this is a heap out-of-bounds write on remote input, integrity impact is possible though code execution has not been demonstrated.

Affected: GStreamer gst-plugins-bad (reproduced on 1.28.3) Fixed: Planned for GStreamer 1.28.5 Fix MR: https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/mergerequests/100 Upstream issue: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/workitems/5173 (confidential) Advisory: GST-SA-2026-0063

Reporter: Clouditera Security; Z.ai Security; NSFOCUS PSIRT Ticket: PSIRTSUPT-19089

Red Hat

Affected Software

1 affected component
GStreamer gst-plugins-bad>1.28.3<=1.28.5

Event History

Jul 6, 2026
Data Sourced
via Red Hat·01:42 PM
DescriptionSeverityAffected Software
Jul 9, 2026
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-59691?

The severity of CVE-2026-59691 is rated as high with a score of 7.1.

2

How do I fix CVE-2026-59691?

To fix CVE-2026-59691, update GStreamer to the latest version that addresses the heap buffer overflow vulnerability.

3

What type of vulnerability is identified in CVE-2026-59691?

CVE-2026-59691 is classified as a heap buffer overflow vulnerability in the GStreamer rfbsrc plugin.

4

What can be exploited in CVE-2026-59691?

CVE-2026-59691 can be exploited when a client connects to a malicious RFB/VNC server that sends improperly encoded updates.

5

What impact does CVE-2026-59691 have on users?

CVE-2026-59691 may allow an attacker to perform an out-of-bounds write, potentially leading to application crashes or arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203