Executive brief
LibVNCClient is a library used by applications to connect to and control remote desktops via the VNC protocol. A vulnerability in how the library handles specific image compression settings allows a malicious VNC server to corrupt the memory of a connecting client. This could lead to the application crashing or, in some scenarios, allow the attacker to gain unauthorized control over the client system.
Technical details
An out-of-bounds (OOB) write vulnerability exists in LibVNCClient's Tight encoding decoder within `src/libvncclient/tight.c`. The decoder utilizes fixed-size 2048-pixel scratch buffers (`tightPrevRow` and `thisRow`) for the Gradient filter but fails to validate if the incoming `FramebufferUpdate` rectangle width exceeds this limit. A malicious VNC server can send a crafted rectangle using Tight encoding with `NoZlib | ExplicitFilter` and the Gradient filter. This results in both heap-based OOB writes (overwriting `rfbClient` structure fields including callback pointers) and stack-based buffer overflows. The vulnerability is reachable upon connection to a compromised or malicious server and was fixed in commit 5b270544b85233668b98161323297d418a8f5fd1.
Affected products
- LibVNC LibVNCClient 0.9.15 and earlier
Timeline
- 2026-05-06: advisory: Initial security advisory published by maintainers
- 2026-05-27: disclosed: CVE-2026-44988 published to NVD