Impact
The vulnerability is a heap buffer overflow caused by the libsoup function soup_uri_decode_data_uri() treating base64 data‑URI payloads as NUL‑terminated strings. When the percent‑decoded payload contains embedded NUL bytes, the function may leave the decoded length uninitialized, and g_base64_decode_inplace() returns a GBytes object whose size is based on this uninitialized value. This allows an out‑of‑bounds read or a crash when an attacker provides a crafted data URI. The weakness is a classic example of an uninitialized read (CWE‑125).
Affected Systems
The flaw is present in the libsoup libraries shipped with Red Hat Enterprise Linux versions 10, 6, 7, 8, and 9. Any application on these distributions that uses soup_uri_decode_data_uri() to handle data URIs may be affected.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is not available, but the lack of a KEV listing suggests no public exploit in the wild at this time. The likely attack vector is remote, via a maliciously crafted data URI that an application processes. Once triggered, the attacker could cause a denial‑of‑service or potentially gain further escalation if the application processes untrusted data in a privileged context.
OpenCVE Enrichment