Bug 2543274 (CVE-2026-102558) - CVE-2026-102558 libsoup: libsoup: Heap buffer overflow during WebSocket receive-buffer growth
Summary: CVE-2026-102558 libsoup: libsoup: Heap buffer overflow during WebSocket recei...
Keywords:
Status: NEW
Alias: CVE-2026-102558
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2543278 2543279 2543280
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-29 16:08 UTC by OSIDB Bzimport
Modified: 2026-09-29 16:24 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-29 16:08:07 UTC
A heap buffer overflow was found in libsoup's WebSocket incoming receive buffer handling.

Incoming frames are accumulated in a GByteArray. With max-incoming-payload-size set to 0 (unlimited), a peer could declare a multi-GiB payload and stream it until the buffer length wrapped in g_byte_array_set_size() while the read still targeted the original offset, writing past the allocation.

Fixed by rejecting payload lengths above what the receive buffer can represent as soon as the frame header is parsed, before buffering the payload (commit 381a474f, libsoup 3.7.3). Such frames are closed as SOUP_WEBSOCKET_CLOSE_TOO_BIG.

References:
https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554 (Bug 6)
https://gitlab.gnome.org/GNOME/libsoup/-/commit/381a474f


Note You need to log in before you can comment on or make changes to this bug.