Sceawere
Vulnerability Detail
CVE-2026-102558UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libsoup WebSocket Heap Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 7h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in libsoup. When max-incoming-payload-size is unlimited (0), SoupWebsocketConnection could grow its incoming GByteArray based on an attacker-controlled frame length until the length wrapped, causing a heap buffer overflow while reading frame data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-09-29T18:17:08.340Z",
"pubdate": "2026-09-29T18:17:08.340Z",
"executiveSummary": "A critical heap-based buffer overflow vulnerability exists in the libsoup library, specifically within the SoupWebsocketConnection component. The flaw arises due to improper handling of WebSocket frame lengths when the max-incoming-payload-size property is set to 0 (unlimited).\nThis vulnerability allows a remote, unauthenticated attacker to trigger memory corruption by providing a specially crafted WebSocket frame. By exploiting the integer wrap-around behavior during the allocation of a GByteArray, an attacker can manipulate the internal buffer management of the library.\nSuccessful exploitation may lead to arbitrary code execution, denial of service, or significant memory corruption within the context of the application utilizing libsoup. Given that WebSocket traffic is often processed at the application layer, the risk to affected systems is high. The vulnerability does not require prior authentication, making it a viable target for remote exploitation via network-accessible services.\nOrganizations relying on libsoup should prioritize updates as soon as vendor patches become available. Until remediation is applied, defensive measures should focus on enforcing strict payload size limits rather than relying on default or unlimited configurations.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of frame size headers within the SoupWebsocketConnection implementation in libsoup. When the max-incoming-payload-size property is configured to 0, representing an unlimited payload size, the logic governing the allocation of the incoming GByteArray fails to account for potential integer overflows.\nThe attack flow begins when a remote attacker initiates a WebSocket connection to a server utilizing a vulnerable version of libsoup. The attacker transmits a WebSocket frame containing an intentionally large length field. Because the implementation relies on the frame length to dynamically resize the GByteArray container, a large, attacker-controlled value can cause the underlying integer calculation to wrap around. For instance, if the length calculation involves an addition or a multiplication that exceeds the maximum value of the data type (e.g., size_t), the resulting value wraps to a small number.\nSubsequently, the library attempts to allocate this wrapped, smaller-than-expected size on the heap. However, the subsequent routine responsible for reading the frame data ignores the actual allocation size and follows the length specified in the original malicious frame header. This disparity between the allocated heap buffer size and the actual number of bytes copied into that buffer results in an out-of-bounds heap write. This memory corruption allows the attacker to overwrite adjacent heap metadata or application-specific objects.\nThe exploitation mechanism relies on heap grooming and the ability to control the contents written beyond the bounds of the GByteArray. An attacker can craft a payload that overwrites function pointers, return addresses, or other critical memory structures to redirect execution flow. The vulnerability is triggered during the frame parsing phase, which occurs during normal WebSocket data transmission; thus, no special privileges are required, and the attacker does not need to be authenticated if the application accepts WebSocket connections from the public internet.\nThe vulnerability is localized to the SoupWebsocketConnection component. Any application or service linked against affected versions of libsoup that parses WebSocket frames is susceptible. The severity of the impact depends on the specific memory layout of the host process at the time of the overflow, potentially leading to immediate process termination (Denial of Service) or a controlled compromise of the host process (Remote Code Execution)."
}