Description
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.
Published: 2026-09-29
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution Potential
Action: Apply Workaround
AI Analysis

Impact

A heap buffer overflow in libsoup is triggered when the ::pong signal is emitted with a GByteArray pointer instead of the documented GBytes. If an application connects a handler that follows the expected GBytes API, a crafted WebSocket Pong frame can corrupt memory or cause an application crash. The resulting heap corruption could allow a malicious actor to compromise the target process, potentially leading to remote code execution.

Affected Systems

Red Hat Enterprise Linux 10, 6, 7, 8, and 9 are affected by the libsoup vulnerability. Any service or application running on these distributions that uses libsoup WebSocket functionality is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.6 classifies this vulnerability as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, indicating no known widespread exploitation yet. The likely attack vector is a remote WebSocket connection from an untrusted peer that sends a malicious Pong frame, triggering the overflow within libsoup. If exploited, the overflow could allow an attacker to alter the program’s memory space and potentially execute arbitrary code or crash the application.

Generated by OpenCVE AI on September 30, 2026 at 01:06 UTC.

Remediation

Vendor Workaround

To mitigate avoid connecting custom handlers to SoupWebsocketConnection::pong, or avoid WebSocket use with untrusted peers.


OpenCVE Recommended Actions

  • Do not attach custom signal handlers to SoupWebsocketConnection::pong, and avoid using WebSocket functionality with untrusted peers as a temporary measure.
  • When Red Hat releases an updated libsoup package that fixes the signal type confusion, upgrade the package immediately.
  • Configure network controls or a reverse proxy to deny or filter untrusted WebSocket connections to applications that use libsoup.

Generated by OpenCVE AI on September 30, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.
Title Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-843
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-29T17:24:13.042Z

Reserved: 2026-09-29T13:19:05.617Z

Link: CVE-2026-102556

cve-icon Vulnrichment

Updated: 2026-09-29T17:24:06.998Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:06.460

Modified: 2026-09-29T21:29:07.663

Link: CVE-2026-102556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:15:04Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')