Upstream information

CVE-2026-59691 at MITRE

Description

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v3 Scores
CVSS detail CNA (Red Hat)
Base Score 7.1
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 10
  • gstreamer1-plugins-bad-free >= 1.26.7-2.el10_2.6
  • gstreamer1-plugins-bad-free-devel >= 1.26.7-2.el10_2.6
  • gstreamer1-plugins-bad-free-libs >= 1.26.7-2.el10_2.6
Patchnames:
RHSA-2026:47180
SUSE Liberty Linux 8
  • gstreamer1-plugins-bad-free >= 1.16.1-9.el8_10.1
  • gstreamer1-plugins-bad-free-devel >= 1.16.1-9.el8_10.1
Patchnames:
RHSA-2026:47731


SUSE Timeline for this CVE

CVE page created: Wed Jul 29 21:54:05 2026
CVE page last modified: Thu Jul 30 15:11:24 2026