Executive brief
libsoup is a networking library used by many applications to handle web communications. A flaw in how it processes WebSocket data allows a malicious server to send specially crafted messages that could cause an application to crash or potentially leak small amounts of memory. This issue occurs because a previous security fix was incomplete, leaving certain types of data transfers unprotected.
Technical details
An out-of-bounds read vulnerability exists in libsoup's WebSocket frame processing. The root cause is an incomplete fix for CVE-2026-0716 (commit 6ff7ef0), where integer overflow guards were only applied to masked frames, leaving unmasked server-to-client frames unprotected. A malicious server can exploit this by sending an unmasked frame with a payload length field near UINT64_MAX. This attack is successful when the client has 'max_incoming_payload_size' set to 0. The vulnerability can lead to a denial of service (crash) or limited information disclosure.
Affected products
- Red Hat libsoup3 3.6.6
- GNOME libsoup 3.6.6
Timeline
- 2026-03-04: patched: Merge request to fix the OOB read in unmasked frames submitted to GNOME libsoup GitLab.
- 2026-06-16: disclosed: Bug reported to Red Hat Bugzilla.
- 2026-07-14: advisory: CVE-2026-12478 published.