libsoup是libsoup团队开源的一个HTTP库。 libsoup存在资源管理错误漏洞,该漏洞源于libsoup的HTTP/2协议实现内存上下文块释放失败,可能导致远程未认证攻击者诱骗连接引擎分配流状态并在清理时泄漏,逐渐消耗系统堆分配,最终导致应用程序崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15711 | 7.5 HIGH | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversize |
| CVE-2026-15709 | 7.5 HIGH | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded de |
| CVE-2026-15714 | 6.5 MEDIUM | Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_str |
| CVE-2026-15712 | 5.9 MEDIUM | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over- |
| CVE-2026-12478 | 4.8 MEDIUM | Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame p |
No comments yet