REDHAT-BUG-2448044: Use After Free

Published Mar 16, 2026
·
Updated

Use-After-Free vulnerability in the HTTP/2 server implementation of the libsoup HTTP library. The issue occurs in the onframerecvcallback() function when processing HTTP/2 frames. During header handling, the function increments an internal callback counter and emits signals such as soupservermessagegotheaders(). If a user-defined signal handler disconnects the client connection during this callback (for example due to authentication failure), the associated SoupServerMessageIOHTTP2 object may be destroyed and freed while still referenced by the callback. When execution returns to the callback, it continues to access the freed io object and attempts to update internal state, resulting in a heap use-after-free condition. An attacker can trigger this issue by sending HTTP/2 requests that cause authentication validation failures, potentially leading to application instability or crashes.

Affected Software

1 affected component
libsoup/libsoup

Event History

Mar 16, 2026
Data Sourced
via Red Hat·02:46 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2448044?

The severity of REDHAT-BUG-2448044 is classified as medium with a risk score of 4.

2

What type of vulnerability is identified in REDHAT-BUG-2448044?

REDHAT-BUG-2448044 describes a Use-After-Free vulnerability in the HTTP/2 server implementation of the libsoup HTTP library.

3

How do I fix REDHAT-BUG-2448044?

To fix REDHAT-BUG-2448044, update the libsoup package to the latest version that patches this vulnerability.

4

What software is affected by REDHAT-BUG-2448044?

The affected software for REDHAT-BUG-2448044 is the libsoup HTTP library.

5

What functions are involved in REDHAT-BUG-2448044?

The on_frame_recv_callback() function is involved in handling the vulnerability as it processes HTTP/2 frames.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203