VDB

CVE-2026-44988

CVE-2026-44988 PUBLISHED CVSS 8.8 HIGH

Reported by GitHub_M · Published May 27, 2026

LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight rectangles whose width is larger than 2048 pixels. A malicious VNC server can send a crafted FramebufferUpdate rectangle using Tight encoding with NoZlib | ExplicitFilter and the Gradient filter. When a LibVNCClient-based client connects, the client processes the server-controlled rectangle width and writes beyond fixed-size Gradient buffers. This vulnerability is fixed with commit 5b270544b85233668b98161323297d418a8f5fd1.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
LibVNClibvncserver<= 0.9.15
LibVNClibvncserver<= 0.9.15, <= 0.9.15, <= 0.9.15

Timeline

  • May 27, 2026 CVE Published
  • May 28, 2026 EPSS Score
  • May 29, 2026 EPSS Score
  • May 29, 2026 Security Advisory
  • May 29, 2026 CVE Updated
  • May 30, 2026 EPSS Score
  • May 31, 2026 EPSS Score
  • Jun 1, 2026 EPSS Score
  • Jun 5, 2026 EPSS Score
  • Jun 7, 2026 Coalition ESS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›