Sceawere
Vulnerability Detail
CVE-2026-102559UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libsoup WebSocket Heap Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 7h ago
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- Attack Type
- Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-09-29T18:17:08.503Z",
"pubdate": "2026-09-29T18:17:08.503Z",
"executiveSummary": "This vulnerability involves a heap-based buffer overflow in libsoup, specifically occurring during the construction of masked WebSocket client frames for large payloads.\nThe flaw originates from an integer truncation error when calculating the size for GByteArray allocations, while the subsequent masking process continues to operate on the original, larger payload length.\nThis mismatch between the allocated buffer size and the actual data processing length leads to out-of-bounds memory writes, potentially allowing an attacker to overwrite adjacent heap memory.\nThe vulnerability affects systems utilizing libsoup for WebSocket communication. Exploitation could lead to application crashes, arbitrary code execution, or unauthorized memory disclosure, depending on the heap layout and the attacker's ability to control the input payload.\nNo specific authentication or specialized privilege levels are inherently required to trigger this flaw if an attacker can force the client to process a maliciously crafted, oversized WebSocket frame.\nThe risk is critical for any service relying on libsoup to handle network-derived WebSocket data, as it compromises the integrity and confidentiality of the affected process.",
"technicalDetails": "The vulnerability is rooted in an integer overflow or truncation issue within the libsoup WebSocket frame masking logic. When the library prepares a masked WebSocket frame for an outgoing payload, it must calculate the necessary buffer size for the GByteArray to store the frame header, the masking key, and the masked data payload.\nThe root cause manifests when the payload size is sufficiently large to trigger a truncation during the conversion of the length variable before it is passed to the GByteArray allocation API. If the allocation function receives a truncated, smaller-than-intended size, it allocates a buffer that is insufficient to hold the complete frame.\nDespite the truncated allocation, the subsequent routine responsible for applying the WebSocket masking operation references the original, full length of the payload. Consequently, the masking function attempts to write the masked data into a buffer that lacks the required capacity, resulting in a heap-based buffer overflow where data is written beyond the boundaries of the allocated heap chunk.\nExploitation involves the following flow: First, an attacker sends or triggers a sequence that forces the libsoup-based client to generate a large WebSocket payload. Second, the client initiates the masking routine, causing the library to calculate an allocation size that undergoes truncation due to integer handling inconsistencies. Third, the GByteArray mechanism allocates a heap segment based on the truncated value. Fourth, the masking loop proceeds to process the data using the original, un-truncated length, writing bytes well past the end of the undersized heap allocation.\nThe impact of this overflow is highly dependent on the heap allocator's state and the specific metadata stored in adjacent heap chunks. An attacker may be able to achieve remote code execution (RCE) by corrupting sensitive pointers or object structures residing on the heap. Even if RCE is not feasible, the overflow will consistently lead to memory corruption, resulting in immediate process termination and a Denial of Service (DoS) condition.\nThe vulnerability is restricted to the network-facing components of libsoup, requiring the application to engage in WebSocket operations. There are no authentication requirements to trigger this condition if the application process is already exposed to attacker-controlled network traffic that influences outgoing frame construction."
}