Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12549

Опубликовано: 22 июн. 2026
Источник: debian
EPSS Низкий

Описание

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3unfixedpackage
libsoup3not-affectedtrixiepackage
libsoup3not-affectedbookwormpackage
libsoup2.4removedpackage
libsoup2.4not-affectedtrixiepackage
libsoup2.4not-affectedbookwormpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2489999

  • https://gitlab.gnome.org/GNOME/libsoup/-/work_items/516

EPSS

Процентиль: 34%
0.00411
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
redhat
больше 2 лет назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
nvd
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

CVSS3: 4.8
github
около 2 месяцев назад

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.

EPSS

Процентиль: 34%
0.00411
Низкий