Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-2436

Опубликовано: 11 фев. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the soup_server_disconnect() function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsoup3Fix deferred
Red Hat Enterprise Linux 6libsoupFix deferred
Red Hat Enterprise Linux 7libsoupFix deferred
Red Hat Enterprise Linux 8libsoupFix deferred
Red Hat Enterprise Linux 9libsoupFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2442909libsoup: libsoup: Denial of Service via use-after-free in SoupServer during TLS handshake

EPSS

Процентиль: 27%
0.00098
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
17 дней назад

[Unknown description]

debian

Описание отсутствует

CVSS3: 6.5
github
2 дня назад

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.

EPSS

Процентиль: 27%
0.00098
Низкий

6.5 Medium

CVSS3