Sceawere

Vulnerability Detail

CVE-2026-102555UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libsoup Data URI Out-of-Bounds Read

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
7h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-09-29T18:17:07.977Z",
  "pubdate": "2026-09-29T18:17:07.977Z",
  "executiveSummary": "A vulnerability has been identified in the libsoup library, specifically within the soup_uri_decode_data_uri() function. The flaw stems from improper handling of base64-encoded data URI payloads containing embedded NUL bytes. When processed, the function erroneously treats these payloads as NUL-terminated strings during the invocation of g_base64_decode_inplace().\nThis logic error results in an uninitialized length being utilized to define the size of the returned GBytes object. An attacker can exploit this by crafting a malicious data URI containing specific NUL-byte injections, leading to an out-of-bounds memory read or an application crash. The vulnerability poses a significant risk to applications relying on libsoup for URI processing, as it can be leveraged to induce denial-of-service conditions or potentially expose sensitive memory contents through the resulting buffer over-read.\nThe vulnerability is accessible to any remote or local actor capable of forcing the application to process a crafted data URI. No specific user interaction beyond the triggering of the URI processing is strictly required, making this a relevant concern for network services or applications parsing untrusted web content.",
  "technicalDetails": "The root cause of this vulnerability lies in the interaction between soup_uri_decode_data_uri() and the GLib utility g_base64_decode_inplace(). In the vulnerable implementation, the library fails to account for the possibility of embedded NUL characters (0x00) within the base64-encoded payload. By treating the payload as a conventional C-style NUL-terminated string, the logic effectively truncates or incorrectly processes the data before it is handed to the base64 decoding routine.\nWhen g_base64_decode_inplace() is executed, it expects accurate length metadata to perform buffer operations. Because the URI decoding process does not sanitize or correctly measure the length of the binary payload, the subsequent calculation for the size of the GBytes output object relies on uninitialized or incorrect length values. This mismatch creates a memory corruption scenario where the system attempts to allocate or read from an invalid memory address range based on the malformed size calculation.\nThe exploitation flow proceeds as follows: First, an attacker constructs a specially crafted data URI. The payload contains a valid base64 sequence interspersed with NUL bytes designed to bypass length checks or mislead the URI decoder. Second, the libsoup library parses the URI, triggering the vulnerable function. Third, the incorrect length calculation occurs, leading the application to treat an improperly sized buffer as valid memory. Finally, when the application subsequently reads or accesses the corrupted GBytes object, the out-of-bounds read occurs, leading to either an immediate segmentation fault (crash) or the leakage of adjacent memory segments into the application's processing logic.\nThis vulnerability is particularly impactful because it affects the core data parsing mechanisms of libsoup. Since the library is often used in browser engines and web-based applications, the exposure extends to any context where untrusted URIs are parsed. The lack of validation on the internal state of the decoded buffer means that the application logic cannot defend against the input once it enters the decoding pipeline. Given that the function operates on memory buffers, there is no requirement for specific authentication or elevated privileges; the vulnerability is strictly dependent on the application's exposure to URI-based inputs.\nThe resulting out-of-bounds read allows an attacker to influence application execution flow or bypass boundary checks, which can be critical for chaining together more complex exploits against the host process."
}
CVE-2026-102555: libsoup Data URI Out-of-Bounds Read (HIGH Severity, CVSS: 8.2) | Sceawere