Executive brief
A vulnerability has been identified in libsoup, a widely used library for handling web requests in GNOME-based applications and Linux environments. An attacker can send specially crafted network traffic to a server using this library, causing it to crash or become unstable. This results in a denial-of-service, potentially disrupting applications that rely on this library for network communication.
Technical details
A use-after-free (UAF) vulnerability exists in the HTTP/2 server implementation of libsoup (CWE-416). The flaw is triggered when a remote, unauthenticated attacker sends specially crafted HTTP/2 requests that result in authentication failures. This sequence causes the application to attempt to access memory that has already been deallocated, leading to memory corruption and application crashes. While Red Hat assigned a CVSS score of 5.3 (Medium), NIST has assigned a score of 7.5 (High) due to the potential for complete service unavailability. Patches have been released for various Red Hat Enterprise Linux versions (libsoup3 packages).
Affected products
- GNOME libsoup3 3.6.5-3.el10_1.11, 3.6.5-3.el10_0.15
- GNOME libsoup
- Red Hat Enterprise Linux 10.0
- Red Hat Enterprise Linux 9.0
- Red Hat Enterprise Linux 8.0
- Red Hat Enterprise Linux 7.0
- Red Hat Enterprise Linux 6.0
Timeline
- 2026-03-17: disclosed: Initial disclosure and CVE assignment
- 2026-05-11: patched: Red Hat released security advisory RHSA-2026:15968
- 2026-05-14: patched: Red Hat released security advisory RHSA-2026:17482
- 2026-05-19: patched: Red Hat released security advisory RHSA-2026:19143