CVE-2026-2443
EUVD-2026-617513.02.2026, 12:16
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | libsoup | - |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsoup-2_4-1 |
| ||||||||||||||||||||
| libsoup-2_4-1-32bit |
| ||||||||||||||||||||
| libsoup-3_0-0 |
| ||||||||||||||||||||
| libsoup-devel |
| ||||||||||||||||||||
| libsoup-lang |
| ||||||||||||||||||||
| libsoup2-devel |
| ||||||||||||||||||||
| libsoup2-lang |
| ||||||||||||||||||||
| typelib-1_0-Soup-2_4 |
| ||||||||||||||||||||
| typelib-1_0-Soup-3_0 |
|
Common Weakness Enumeration