Sceawere

Vulnerability Detail

CVE-2026-102556UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libsoup WebSocket Pong Type Confusion

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Access of Resource Using Incompatible Type ('Type Confusion')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-09-29T17:17:06.460Z",
  "pubdate": "2026-09-29T17:17:06.460Z",
  "executiveSummary": "A critical type confusion vulnerability exists in the libsoup library concerning the handling of WebSocket Pong frames.\nThe vulnerability arises due to a signature mismatch between the defined GObject signal and the actual data structure passed during execution.\nSpecifically, SoupWebsocketConnection incorrectly emits the ::pong signal using a GByteArray pointer while the signal definition expects a GBytes object.\nThis mismatch leads to memory safety issues, potentially resulting in heap corruption or application crashes when processing malicious WebSocket frames.\nThe flaw affects applications utilizing the libsoup WebSocket implementation that have connected a signal handler expecting the documented GBytes API.\nAn attacker capable of initiating a WebSocket connection and transmitting a crafted Pong frame can trigger this condition, leading to denial-of-service or potential arbitrary code execution depending on the application's memory layout and handler implementation.\nNo specific authentication is required if the target application exposes WebSocket functionality to the network.\nThe impact is significant as it compromises the integrity of memory operations within the calling application.",
  "technicalDetails": "The root cause of this vulnerability is a mismatch in the GObject signal emission mechanism within the libsoup WebSocket implementation, specifically located in SoupWebsocketConnection.\nThe library defines the ::pong signal signature to receive a GBytes object as its payload argument. However, during the internal processing of an incoming WebSocket Pong frame, the implementation emits this signal by passing a pointer to a GByteArray structure instead.\nThis discrepancy triggers a type confusion vulnerability when an application-level handler is connected to the ::pong signal. When the signal is emitted, the handler, expecting the memory layout and reference counting behavior of a GBytes object, receives a pointer to a GByteArray structure instead.\nSince GBytes and GByteArray possess different memory structures and field offsets, the handler attempts to access or interpret the provided pointer based on the GBytes ABI. For instance, if the handler attempts to retrieve the data pointer or length using GBytes accessors on a GByteArray instance, it will perform out-of-bounds memory access or read from an incorrect memory offset.\nThe attack flow begins when an attacker establishes a WebSocket connection with a vulnerable application. The attacker then sends a crafted WebSocket Pong frame. Upon receipt, SoupWebsocketConnection parses the frame and triggers the signal emission process. Because the underlying emission function passes the incorrect pointer, the application's signal handler is invoked with corrupted data context.\nIf the signal handler attempts to manipulate or deallocate the object using GBytes-specific functions, it can result in immediate heap corruption, as the handler may treat parts of the GByteArray struct as pointer addresses or control data. This behavior can be exploited by an attacker to overwrite critical memory structures or trigger a segmentation fault.\nThis vulnerability is reachable remotely over the network, as the processing of WebSocket frames is inherent to the protocol implementation. Successful exploitation does not require prior authentication if the WebSocket service is exposed. The severity is exacerbated by the fact that many developers follow standard API documentation, leading to a high likelihood of affected applications blindly trusting the signal payload type, thereby facilitating the exploitation of the type confusion during the callback execution."
}
CVE-2026-102556: libsoup WebSocket Pong Type Confusion (HIGH Severity, CVSS: 8.6) | Sceawere