Impact
A flaw in libsoup’s WebSocket permessage‑deflate extension causes the inflate() buffer. When a remote, unauthenticated attacker sends a highly compressed payload, the library allocates unbounded memory, resulting in an Out‑of‑Memory crash that disables the service. This vulnerability represents an uncontrolled resource consumption409) and leads to denial of service to affected applications.
Affected Systems
The issue impacts Red Hat Enterprise Linux 6, 7, 8, 9, and 10, as they ship the vulnerable libsoup package. Any running libsoup that accept WebSocket connections on these operating systems are therefore susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate severity. The EPSS score of < 1% reflects that exploitation is considered unlikely at present. No listing in the KEV catalog suggests no known active exploits. The likely attack vector is inferred to be remote, requiring the attacker to send a crafted WebSocket frame over an open network connection to a vulnerable service. The CNA states that no official workaround is available, and the vulnerability remains exploitable because the safe‑size check is disabled by default for client connections.
OpenCVE Enrichment