Fedora Account System
Red Hat Associate
Red Hat Customer
A heap buffer overflow was found in libsoup's client-side WebSocket frame construction / masking path. Outgoing frames are built in a GByteArray. For a send payload larger than the array can represent (at/above ~2^31), g_byte_array_sized_new() / append truncated the length while xor_with_mask() still iterated the full attacker-/caller-controlled length, writing past the small allocation during masking. Fixed by rejecting outgoing payloads above MAX_OUTGOING_PAYLOAD_SIZE both before and after extensions process the payload (commit d7f074f8, libsoup 3.7.3). References: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554 (Bug 7) https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8