NIXPKGS-2026-2511
GitHub issue
published 9 hours ago
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
Permalink
CVE-2026-85197
7.6 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package libsoup_2_4
- @LeSuisse accepted
- @LeSuisse published on GitHub
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
References
Affected products
libsoup
libsoup3
Matching in nixpkgs
Ignored packages (1)
pkgs.libsoup_2_4
None
Package maintainers
-
@thunze Tom Hunze
-
@nekowinston winston <hey@winston.sh>
-
@theCapypara Marco Köpcke <hello@capypara.de>
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>