Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw in libsoup’s `permessage-deflate` WebSocket extension allows a remote attacker to cause a Denial of Service via memory exhaustion. The internal `inflate()` loop resizes its buffer dynamically without enforcing an upper limit *during* decompression. Because size checks are either performed only on the compressed wire-payload or executed too late (after inflation completes), a small decompression bomb can trigger an immediate Out-of-Memory (OOM) crash on both client and server applications.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:68235 https://access.redhat.com/errata/RHSA-2026:68235
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:68234 https://access.redhat.com/errata/RHSA-2026:68234
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:68612 https://access.redhat.com/errata/RHSA-2026:68612
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:69108 https://access.redhat.com/errata/RHSA-2026:69108
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:69297 https://access.redhat.com/errata/RHSA-2026:69297
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:69863 https://access.redhat.com/errata/RHSA-2026:69863
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:70599 https://access.redhat.com/errata/RHSA-2026:70599
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:70598 https://access.redhat.com/errata/RHSA-2026:70598
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:71389 https://access.redhat.com/errata/RHSA-2026:71389