{"id":"CVE-2026-52720","title":"A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client)","summary":"A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that exte…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-122","CWE-122"],"published":"2026-06-15","updated":"2026-07-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52720","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:36749","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36834","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:37130","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47069","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47070","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47071","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47075","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47076","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47176","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-52720","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486731","label":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/work_items/5105","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36749","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:36834","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:37130","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-52720","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486731","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52720.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd"],"epss":0.0118,"epssPercentile":0.66319,"ingestedAt":"2026-07-28T21:39:18.064Z","slug":"CVE-2026-52720","body":"## Overview\n\nA heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}