以下是对该漏洞描述信息的中文翻译: libsoup 的 HTTP Range 头处理中存在一个算法复杂度缺陷,该缺陷在 CVE-2025-32907 修复后依然存续。 CVE-2025-32907 解决了当客户端在单个 Range 头中重复指定同一范围多次时导致的内存放大问题。提交 修正了 中 的合并正确性问题,但合并循环仍对每个合并后的元素使用 来移除已合并的范围。由于 是连续内存结构,每次移除数组中间的元素都会执行 O(N) 复杂度的内存移动(memmove)。当提供大量相同的可满足范围(例如, 重复数千次)时
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79992 | 7.8 HIGH | Emacs: local shell command injection through the user field in emacs tramp |
| CVE-2026-79655 | 7.8 HIGH | Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targ |
| CVE-2026-80186 | 7.6 HIGH | Bluez: stack overflow in name2utf8 causes dos and potential code execution |
| CVE-2026-78701 | 6.5 MEDIUM | 389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall d |
| CVE-2026-78322 | 6.5 MEDIUM | File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar hand |
| CVE-2026-79717 | 6.4 MEDIUM | Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restrict |
| CVE-2026-79652 | 5.9 MEDIUM | Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce cons |
| CVE-2026-80185 | 5.7 MEDIUM | Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary cod |
| CVE-2026-80101 | 4.4 MEDIUM | Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-l |
No comments yet