REDHAT-BUG-2543231: Buffer Overflow
A heap buffer overflow was found in libsoup WebSocket fragmented-message reassembly.
Reassembled messages are stored in a GByteArray (length typed as guint). A sequence of fragments (or extension expansion) that grew the message past GMAXINT caused gbytearraysetsize() / related growth APIs to truncate the size while surrounding code continued to use the full length, corrupting the heap. Upstream notes interaction with older GLib (e.g. 2.70) growth behavior.
Fixed by rejecting reassembly that would exceed what a GByteArray can safely hold, independently of max-total-message-size (commit d7f074f8, libsoup 3.7.3).
References: https://gitlab.gnome.org/GNOME/libsoup/-/workitems/554 (Bug 5) https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libsoupto a version that resolves this vulnerability.Fixed in 3.7.3Patch d7f074f8
Event History
Frequently Asked Questions
What does an attacker need to do to trigger the overflow?
An attacker needs to supply a fragmented WebSocket message, or data whose WebSocket extension processing expands it, so that reassembly grows beyond what a GByteArray can safely hold. The issue occurs when the accumulated message exceeds G_MAXINT.
Are configured WebSocket message-size limits sufficient mitigation?
No. The fix rejects reassembly that exceeds the safe GByteArray size independently of the max-total-message-size setting, so that setting alone does not address this condition.
Which component versions contain the fix?
The described fix is in libsoup 3.7.3 and rejects oversized reassembly before GByteArray growth can truncate the size. The data also notes that older GLib behavior, for example GLib 2.70, interacts with the vulnerable growth path.