libsoup 中发现了一个缺陷。当客户端从非可轮询(non-pollable)输入流发送 HTTP/2 请求体时,库可能会缓冲比当前流控窗口允许范围更多的数据。恶意的 HTTP/2 服务器可以在该缓冲读取仍在进行期间缩小 。随后,客户端会在没有运行时边界检查的情况下,将完整缓冲区复制到较小的 DATA 回调中,这可能导致进程终止或 HTTP/2 会话失败。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85197 | 7.6 HIGH | Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway d |
| CVE-2026-81665 | 7.5 HIGH | Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmente |
| CVE-2026-81666 | 6.5 MEDIUM | Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message |
| CVE-2026-85769 | 6.5 MEDIUM | Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_ |
| CVE-2026-76925 | 5.8 MEDIUM | Flatpak: flatpak: toctou race condition allows symlink redirection |
No comments yet