Use-After-Free Vulnerability in Libsoup's SoupServer Affects Red Hat Products
CVE-2026-2436
What is CVE-2026-2436?
A use-after-free vulnerability has been identified in libsoup's SoupServer, which can be exploited by a remote attacker. Specifically, this flaw occurs in the soup_server_disconnect() function, where connection objects are freed prematurely, potentially while a TLS handshake is still in progress. If the handshake is completed after the object has been deallocated, this results in accessing a dangling pointer, subsequently leading to a server crash and a potential Denial of Service. It is essential for users to apply the latest security patches to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved