Heap Out-of-Bounds Read in Libsoup Affects GNOME Products
CVE-2026-12548
4.2MEDIUM
What is CVE-2026-12548?
A vulnerability has been identified in libsoup, involving a heap out-of-bounds read flaw. This issue occurs during the parsing of multipart HTTP messages, where an integer type mismatch can lead to the incorrect truncation of the length parameter in the soup_headers_parse() function. Consequently, a remote attacker may exploit this flaw to cause application crashes or potentially access sensitive heap memory contents. Users relying on libsoup should be aware of this vulnerability and consider applying necessary patches to safeguard their applications.
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank linhlhq (Yes We Hack) for reporting this issue.