Fedora Account System
Red Hat Associate
Red Hat Customer
A heap buffer overflow condition was found in libsoup's soup_uri_decode_data_uri(). After percent-decoding a data URI payload marked ;base64, the code called g_base64_decode_inplace(), which measures input with strlen(). Percent-decoded content can contain embedded NUL bytes (for example data:;base64,A%00B), so the measured length was too short. g_base64_decode_inplace() returned without writing a valid output length; the uninitialized length was then stored as the size of the returned GBytes, allowing callers to read past the allocation. Fixed upstream by decoding with g_base64_decode_step() using the real buffer length (commit e4f03226, libsoup 3.7.3). References: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554 (Bug 1) https://gitlab.gnome.org/GNOME/libsoup/-/commit/e4f03226