REDHAT-BUG-2543231: Buffer Overflow

Published Sep 29, 2026
·
Updated

A heap buffer overflow was found in libsoup WebSocket fragmented-message reassembly.

Reassembled messages are stored in a GByteArray (length typed as guint). A sequence of fragments (or extension expansion) that grew the message past GMAXINT caused gbytearraysetsize() / related growth APIs to truncate the size while surrounding code continued to use the full length, corrupting the heap. Upstream notes interaction with older GLib (e.g. 2.70) growth behavior.

Fixed by rejecting reassembly that would exceed what a GByteArray can safely hold, independently of max-total-message-size (commit d7f074f8, libsoup 3.7.3).

References: https://gitlab.gnome.org/GNOME/libsoup/-/workitems/554 (Bug 5) https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8

Affected Software

1 affected component
Gnome libsoup<3.7.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade libsoup to a version that resolves this vulnerability.

    Fixed in 3.7.3Patch d7f074f8

Event History

Sep 29, 2026
Data Sourced
via Red Hat·03:08 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What does an attacker need to do to trigger the overflow?

An attacker needs to supply a fragmented WebSocket message, or data whose WebSocket extension processing expands it, so that reassembly grows beyond what a GByteArray can safely hold. The issue occurs when the accumulated message exceeds G_MAXINT.

2

Are configured WebSocket message-size limits sufficient mitigation?

No. The fix rejects reassembly that exceeds the safe GByteArray size independently of the max-total-message-size setting, so that setting alone does not address this condition.

3

Which component versions contain the fix?

The described fix is in libsoup 3.7.3 and rejects oversized reassembly before GByteArray growth can truncate the size. The data also notes that older GLib behavior, for example GLib 2.70, interacts with the vulnerable growth path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203