Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0250

NIXPKGS-2026-0250
published on 15 Feb 2026
updated 6 days, 10 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package tests.pkg-config.defaultPkgConfigPackages."libsoup-gnome-2.4"
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

Affected products

libsoup
libsoup3

Matching in nixpkgs

Package maintainers

Upstream issue: https://gitlab.gnome.org/GNOME/libsoup/-/issues/487
Upstream patches:
* https://gitlab.gnome.org/GNOME/libsoup/-/commit/739bf7cb509c20141093d5a7f553007c8af81129
* https://gitlab.gnome.org/GNOME/libsoup/-/commit/00665d626255868ff4b6a30534f46e742478e232