GStreamer rfbsrc plugin heap buffer overflow via Hextile
CVE-2026-59691 Published on July 9, 2026
Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer
A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.
Vulnerability Analysis
CVE-2026-59691 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and a high impact on availability.
Timeline
Reported to Red Hat.
Made public. 2 days later.
Weakness Type
What is a Memory Corruption Vulnerability?
The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.
CVE-2026-59691 has been classified to as a Memory Corruption vulnerability or weakness.
Products Associated with CVE-2026-59691
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Enterprise Linux 10:- Version 0:1.26.7-2.el10_2.6 and below * is unaffected.
- Version 0:1.24.11-3.el10_0.6 and below * is unaffected.
- Version 0:1.10.4-7.el7_9 and below * is unaffected.
- Version 0:1.16.1-9.el8_10.1 and below * is unaffected.
- Version 0:1.16.1-4.el8_6.4 and below * is unaffected.
- Version 0:1.16.1-4.el8_6.4 and below * is unaffected.
- Version 0:1.16.1-4.el8_8.4 and below * is unaffected.
- Version 0:1.16.1-4.el8_8.4 and below * is unaffected.
- Version 0:1.22.12-7.el9_8.3 and below * is unaffected.
- Version 0:1.22.1-6.el9_4.6 and below * is unaffected.
- Version 0:1.22.12-5.el9_6.6 and below * is unaffected.