Bug 2543285 (CVE-2026-102559) - CVE-2026-102559 libsoup: libsoup: Heap buffer overflow during WebSocket client-frame masking
Summary: CVE-2026-102559 libsoup: libsoup: Heap buffer overflow during WebSocket clien...
Keywords:
Status: NEW
Alias: CVE-2026-102559
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-29 16:39 UTC by OSIDB Bzimport
Modified: 2026-09-29 16:47 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-29 16:39:50 UTC
A heap buffer overflow was found in libsoup's client-side WebSocket frame construction / masking path.

Outgoing frames are built in a GByteArray. For a send payload larger than the array can represent (at/above ~2^31), g_byte_array_sized_new() / append truncated the length while xor_with_mask() still iterated the full attacker-/caller-controlled length, writing past the small allocation during masking.

Fixed by rejecting outgoing payloads above MAX_OUTGOING_PAYLOAD_SIZE both before and after extensions process the payload (commit d7f074f8, libsoup 3.7.3).

References:
https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554 (Bug 7)
https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8


Note You need to log in before you can comment on or make changes to this bug.