libsoup是libsoup团队开源的一个HTTP库。 libsoup存在缓冲区错误漏洞,该漏洞源于libsoup的多部分处理子系统中soup_multipart_input_stream_read_headers函数对传入的多部分边界字符串大小限制或验证不足,可能导致远程未经身份验证的攻击者通过处理特制HTTP响应造成越界读取,从而导致服务拒绝或读取未授权内存元数据片段。以下版本受到影响:Red Hat Enterprise Linux 10版本、Red Hat Enterprise Linux 8版
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15711 | 7.5 HIGH | Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversize |
| CVE-2026-15709 | 7.5 HIGH | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded de |
| CVE-2026-15713 | 5.9 MEDIUM | Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via m |
| CVE-2026-15712 | 5.9 MEDIUM | Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over- |
| CVE-2026-12478 | 4.8 MEDIUM | Libsoup: incomplete fix for cve-2026-0716: out-of-bounds read in libsoup websocket frame p |
No comments yet