Heap Corruption Vulnerability in libsoup Affects Red Hat Products
CVE-2026-102557

8.6HIGH

What is CVE-2026-102557?

A flaw in libsoup affects the handling of fragmented WebSocket messages, where the implementation fails to properly cap the total message size against the limits of the underlying buffer. This oversight allows a remote peer to send message fragments that exceed intended limits, potentially leading to heap corruption or application crashes. Mitigation measures should be taken to limit exposure and ensure safe communication through WebSocket protocols.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Hongduo Zhao for reporting this issue.
.