Junglewise Threat Intelligence

CVE-2026-15712: GNOME libsoup heap buffer over-read in HTTP/2 GOAWAY frame parsing

CVE-2026-15712 · Severity: medium · CVSS 5.9 · Published 2026-07-14

Technologies: Gnome Libsoup, Red Hat Enterprise Linux 10. Vendors: Gnome, Red Hat.

Executive brief

A security vulnerability exists in libsoup, a widely used HTTP client/server library for GNOME and Linux applications. When processing specific network signals (HTTP/2 GOAWAY frames), the library may attempt to read data beyond its allocated memory because it incorrectly assumes the data is properly terminated. This can lead to an immediate application crash, causing a denial of service, or potentially allow an attacker to view fragments of sensitive information stored in the system's memory.

Technical details

A heap buffer over-read exists in libsoup (versions 3.0 through 3.7.0) within the `on_frame_recv_callback()` function of the HTTP/2 backend (`soup-client-message-io-http2.c`). The vulnerability occurs when the library processes an HTTP/2 GOAWAY frame containing 'Additional Debug Data'. The parser passes this data to `h2_debug()` using a `%s` format string, which assumes a NUL-terminated C-string. However, the underlying `nghttp2` library allocates this buffer without a NUL terminator. An unauthenticated remote attacker can send a malformed GOAWAY frame to trigger an out-of-bounds read. This typically results in a denial of service (application crash) or potential information disclosure, though the over-read is only triggered when debug logging is enabled (e.g., `G_MESSAGES_DEBUG=libsoup-http2`).

Affected products

  • GNOME libsoup 3.0 to 3.7.0
  • Red Hat Red Hat Enterprise Linux 10 affected

Timeline

  • 2026-02-13: disclosed: Initial report via YesWeHack
  • 2026-07-14: advisory: CVE published and NVD record created

References

Related threats