Heap Use-After-Free Flaw in GNOME Applications Affects libsoup
CVE-2026-85197
7.6HIGH
What is CVE-2026-85197?
A critical flaw exists in the libsoup component utilized by GNOME applications, specifically within its HTTP/2 client implementation. This vulnerability allows a malicious HTTP/2 server or an attacker conducting a Man-in-the-Middle (MITM) assault to exploit a heap use-after-free condition. This scenario is triggered when a file is uploaded using HTTP/2, and the server unexpectedly sends a GOAWAY frame during the asynchronous file read process. Such exploitation can lead to memory corruption, which may result in the disclosure of sensitive information or enable arbitrary code execution.
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Naresh Kandula (Nottiboy_1337) for reporting this issue.