CVE-2026-12548
EUVD-2026-4636321.07.2026, 19:17
A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application using libsoup or potentially disclose heap memory contents.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | libsoup | - |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| libsoup-2_4-1 |
| ||||||||
| libsoup2-devel |
| ||||||||
| libsoup2-lang |
| ||||||||
| typelib-1_0-Soup-2_4 |
|
Common Weakness Enumeration