Heap Use-After-Free Flaw in GNOME Applications Affects libsoup
CVE-2026-85197

7.6HIGH

What is CVE-2026-85197?

A critical flaw exists in the libsoup component utilized by GNOME applications, specifically within its HTTP/2 client implementation. This vulnerability allows a malicious HTTP/2 server or an attacker conducting a Man-in-the-Middle (MITM) assault to exploit a heap use-after-free condition. This scenario is triggered when a file is uploaded using HTTP/2, and the server unexpectedly sends a GOAWAY frame during the asynchronous file read process. Such exploitation can lead to memory corruption, which may result in the disclosure of sensitive information or enable arbitrary code execution.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Naresh Kandula (Nottiboy_1337) for reporting this issue.
.