REDHAT-BUG-2543224: Buffer Overflow

Published Sep 29, 2026
·
Updated

A heap buffer overflow condition was found in libsoup's soupuridecodedatauri().

After percent-decoding a data URI payload marked ;base64, the code called gbase64decodeinplace(), which measures input with strlen(). Percent-decoded content can contain embedded NUL bytes (for example data:;base64,A%00B), so the measured length was too short. gbase64decodeinplace() returned without writing a valid output length; the uninitialized length was then stored as the size of the returned GBytes, allowing callers to read past the allocation.

Fixed upstream by decoding with gbase64decodestep() using the real buffer length (commit e4f03226, libsoup 3.7.3).

References: https://gitlab.gnome.org/GNOME/libsoup/-/workitems/554 (Bug 1) https://gitlab.gnome.org/GNOME/libsoup/-/commit/e4f03226

Affected Software

1 affected component
Gnome libsoup<3.7.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade libsoup to a version that resolves this vulnerability.

    Fixed in 3.7.3Patch e4f03226

Event History

Sep 29, 2026
Data Sourced
via Red Hat·02:47 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What input is needed to trigger the issue?

An attacker needs to supply a data URI whose payload is marked ;base64 and contains percent-encoded data that becomes an embedded NUL byte after decoding, such as data:;base64,A%00B. The embedded NUL causes the base64 decoder to measure a shorter length than the actual buffer.

2

What is the impact after triggering the overflow condition?

The invalid decoded-length value is stored as the size of the returned GBytes object. Callers may then read beyond the allocated buffer.

3

Which fix addresses this issue?

The upstream fix replaces the in-place base64 decoding path with g_base64_decode_step(), using the real buffer length. It is identified by upstream commit e4f03226 and is included in libsoup 3.7.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203