Impact
A heap buffer overflow in libsoup is triggered when the ::pong signal is emitted with a GByteArray pointer instead of the documented GBytes. If an application connects a handler that follows the expected GBytes API, a crafted WebSocket Pong frame can corrupt memory or cause an application crash. The resulting heap corruption could allow a malicious actor to compromise the target process, potentially leading to remote code execution.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, and 9 are affected by the libsoup vulnerability. Any service or application running on these distributions that uses libsoup WebSocket functionality is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies this vulnerability as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. The likely attack vector is a remote WebSocket connection from an untrusted peer that sends a malicious Pong frame, triggering the overflow within libsoup. If exploited, the overflow could allow an attacker to alter the program’s memory space and potentially execute arbitrary code or crash the application.
OpenCVE Enrichment