← Terug naar overzicht

CVE-2026-50538 affects LibVNCClient versions 0.9.12 through 0.9.15, a widely used VNC client library. A malicious or man-in-the-middle VNC server can trigger an out-of-bounds heap write with attacker-controlled length, contents, and offset by sending a single FramebufferUpdate packet upon connection. No authentication is required to exploit this vulnerability. The flaw unconditionally crashes any connecting client, constituting a denial-of-service condition. Researchers also demonstrated successful code execution by overwriting an application callback pointer, redirecting execution to attacker-chosen code. The vulnerability works in default builds with default settings, making it trivially exploitable. A patch has been issued via commit 540332be3e0acc566fa64da6f1b4680c72c724dd in the LibVNC/libvncserver repository.

Affected products

  • LibVNCClient 0.9.12
  • LibVNCClient 0.9.13
  • LibVNCClient 0.9.14
  • LibVNCClient 0.9.15
  • libvncserver

Related CVE's

  • CVE-2026-50538

Categories

  • Network Infrastructure
  • Zero-Day Vulnerabilities