{"schema_version":"1.7.2","id":"OESA-2026-4008","modified":"2026-09-25T01:27:09Z","published":"2026-09-25T01:27:09Z","upstream":["CVE-2026-15709","CVE-2026-15712","CVE-2026-15713"],"summary":"libsoup3 security update","details":"Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in libsoup&apos;s WebSocket implementation when using the permessage-deflate extension. The extension&apos;s decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).(CVE-2026-15709)\n\nA heap buffer over-read vulnerability was discovered in libsoup&apos;s (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the &quot;Additional Debug Data&quot; payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.(CVE-2026-15712)\n\nA vulnerability was found in libsoup&apos;s HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system&apos;s heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash.(CVE-2026-15713)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP4","name":"libsoup3","purl":"pkg:rpm/openEuler/libsoup3&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.5-26.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["libsoup3-3.4.5-26.oe2403sp4.aarch64.rpm","libsoup3-debuginfo-3.4.5-26.oe2403sp4.aarch64.rpm","libsoup3-debugsource-3.4.5-26.oe2403sp4.aarch64.rpm","libsoup3-devel-3.4.5-26.oe2403sp4.aarch64.rpm"],"noarch":["libsoup3-help-3.4.5-26.oe2403sp4.noarch.rpm"],"src":["libsoup3-3.4.5-26.oe2403sp4.src.rpm"],"x86_64":["libsoup3-3.4.5-26.oe2403sp4.x86_64.rpm","libsoup3-debuginfo-3.4.5-26.oe2403sp4.x86_64.rpm","libsoup3-debugsource-3.4.5-26.oe2403sp4.x86_64.rpm","libsoup3-devel-3.4.5-26.oe2403sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4008"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15709"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15712"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15713"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"database_specific":{"severity":"High"}}
