Fedora Account System
Red Hat Associate
Red Hat Customer
A type-confusion heap overflow was found in libsoup's WebSocket Pong handling. SoupWebsocketConnection::pong is declared to deliver a GBytes payload, but receive_pong() emitted a GByteArray pointer via g_signal_emit() and then unreffed the GByteArray. Handlers that treated the argument as GBytes (as documented) operated on the wrong object layout, resulting in heap memory corruption / overflow conditions under ASan. Fixed upstream by converting the buffer with g_byte_array_free_to_bytes() before emission (commit d2cbaf25, libsoup 3.7.3). References: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554 (Bug 2) https://gitlab.gnome.org/GNOME/libsoup/-/commit/d2cbaf25