A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VN…
高危 CVSS 8.8
摘要
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
Lint 边界警告 (1)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5105
数据来源
- NVD DATABASE
原始链接
- https://access.redhat.com/errata/RHSA-2026:36749
- https://access.redhat.com/errata/RHSA-2026:36834
- https://access.redhat.com/errata/RHSA-2026:37130
- https://access.redhat.com/errata/RHSA-2026:47069
- https://access.redhat.com/errata/RHSA-2026:47070
- https://access.redhat.com/errata/RHSA-2026:47071
- https://access.redhat.com/errata/RHSA-2026:47075
- https://access.redhat.com/errata/RHSA-2026:47076
- https://access.redhat.com/security/cve/CVE-2026-52720
- https://bugzilla.redhat.com/show_bug.cgi?id=2486731
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5105
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52720.json
- https://access.redhat.com/errata/RHSA-2026:47176
时间线
- nvd_ingest NVD