Bug 2543224 (CVE-2026-102555) - CVE-2026-102555 libsoup: libsoup: Heap buffer overflow via uninitialized length in data-URI base64 decoding
Summary: CVE-2026-102555 libsoup: libsoup: Heap buffer overflow via uninitialized leng...
Keywords:
Status: NEW
Alias: CVE-2026-102555
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2543268 2543269 2543270
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-29 14:47 UTC by OSIDB Bzimport
Modified: 2026-09-29 16:15 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-29 14:47:10 UTC
A heap buffer overflow condition was found in libsoup's soup_uri_decode_data_uri().

After percent-decoding a data URI payload marked ;base64, the code called g_base64_decode_inplace(), which measures input with strlen(). Percent-decoded content can contain embedded NUL bytes (for example data:;base64,A%00B), so the measured length was too short. g_base64_decode_inplace() returned without writing a valid output length; the uninitialized length was then stored as the size of the returned GBytes, allowing callers to read past the allocation.

Fixed upstream by decoding with g_base64_decode_step() using the real buffer length (commit e4f03226, libsoup 3.7.3).

References:
https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554 (Bug 1)
https://gitlab.gnome.org/GNOME/libsoup/-/commit/e4f03226


Note You need to log in before you can comment on or make changes to this bug.