libsoup是libsoup团队开源的一个HTTP库。 libsoup存在缓冲区错误漏洞,该漏洞源于libsoup中的HTTP/2连接跟踪框架处理GOAWAY帧时不当处理“Additional Debug Data”有效载荷,假定数据流为以NUL终止的C字符串,且解析器在读取数据前缺乏严格长度边界验证,可能导致远程未经身份验证的攻击者发送缺少适当空分隔符的特制GOAWAY帧,造成堆缓冲区越界读取,触发应用程序崩溃导致拒绝服务,或可能暴露内存内容。以下版本受到影响:libsoup 3.0版本至3.7.0版
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15711 | 7.5 HIGH | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversize |
| CVE-2026-15709 | 7.5 HIGH | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded de |
| CVE-2026-15714 | 6.5 MEDIUM | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_str |
| CVE-2026-15713 | 5.9 MEDIUM | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via m |
| CVE-2026-12478 | 4.8 MEDIUM | Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame p |
No comments yet