Sceawere

Vulnerability Detail

CVE-2026-102560UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libsoup Heap Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
7h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in libsoup. When the permessage-deflate WebSocket extension compresses a very large outgoing message, truncated size calculations used for GByteArray growth could wrap, causing zlib to write past the allocated buffer and resulting in a heap buffer overflow.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-09-29T18:17:08.750Z",
  "pubdate": "2026-09-29T18:17:08.750Z",
  "executiveSummary": "A critical heap-based buffer overflow vulnerability exists in libsoup due to improper integer handling during WebSocket permessage-deflate compression operations.\nThe flaw originates from an integer wrap-around vulnerability within the GByteArray memory allocation logic when calculating the buffer size required for large outgoing messages processed by zlib.\nAn unauthenticated, remote attacker can trigger this condition by supplying a crafted, disproportionately large WebSocket message, forcing the application to perform insufficient memory allocation.\nSuccessful exploitation results in out-of-bounds memory corruption, potentially leading to arbitrary code execution or a denial-of-service condition depending on the application context and memory layout.\nThis vulnerability poses a significant risk to systems utilizing libsoup for WebSocket communication, particularly in high-traffic or untrusted network environments where large message exchanges are permitted.\nNo specific authentication is required to initiate the attack, as the flaw is triggered during the processing of incoming data streams processed by the library's WebSocket implementation.",
  "technicalDetails": "The vulnerability resides in the libsoup library's WebSocket implementation, specifically within the logic handling the permessage-deflate extension. When a WebSocket application attempts to send a large data frame, libsoup invokes zlib compression routines to reduce the payload size according to the negotiated protocol parameters.\nThe root cause is a vulnerability in the dynamic resizing logic for the internal GByteArray structure used to hold the compressed output. During the calculation of the required memory buffer, the arithmetic operations involving the size of the outgoing message are susceptible to integer wrapping if the resulting value exceeds the maximum capacity of the integer type used for the length calculation.\nWhen this wrapping occurs, the library allocates a memory buffer significantly smaller than what is required by the zlib compression state. Consequently, as the zlib engine proceeds to compress the input data, it writes the output into the undersized heap buffer, resulting in a heap buffer overflow. This allows the compressor to write data past the intended boundary of the allocated memory segment.\nThe attack flow begins when an attacker establishes a WebSocket connection with a vulnerable libsoup-based client or server that has the permessage-deflate extension enabled. The attacker sends a carefully crafted large message designed to trigger the specific calculation path that results in the integer wrap-around. Once the library logic performs the flawed size calculation and subsequent allocation, the zlib compression process initiates the out-of-bounds write.\nThe impact of this overflow depends on the heap layout and the proximity of sensitive structures to the GByteArray buffer. An attacker may leverage this memory corruption to overwrite adjacent heap metadata, function pointers, or application-specific objects. If control flow can be redirected through this corruption, it may facilitate arbitrary code execution under the security context of the affected process. In scenarios where exploitation for code execution is not viable, the memory corruption will likely lead to an immediate crash, resulting in a denial-of-service."
}
CVE-2026-102560: libsoup Heap Buffer Overflow (HIGH Severity, CVSS: 8.6) | Sceawere