Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-2443

Опубликовано: 13 фев. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.6-1package
libsoup3no-dsatrixiepackage
libsoup3no-dsabookwormpackage
libsoup2.4removedpackage
libsoup2.4no-dsatrixiepackage
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/487

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/508

  • Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9964993a32b2fa734a6b5ba2d465c2c14e22de17 (3.6.6)

  • Followup: https://gitlab.gnome.org/GNOME/libsoup/-/commit/b00665d626255868ff4b6a30534f46e742478e232 (3.6.6)

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

CVSS3: 5.3
redhat
около 1 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

CVSS3: 5.3
nvd
около 1 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

CVSS3: 5.3
msrc
около 1 месяца назад

Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure

CVSS3: 5.3
github
около 1 месяца назад

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the library may improperly validate requested byte ranges. In certain build configurations, this could allow a remote attacker to access portions of server memory beyond the intended response. Exploitation requires a vulnerable configuration and access to a server using the embedded SoupServer component.

EPSS

Процентиль: 12%
0.0004
Низкий