Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92409.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92409
Upstream
  • CVE-2026-15712
Published
2026-07-14T19:16:51Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-15712 affecting package libsoup 3.4.4-16
Details

A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the "Additional Debug Data" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.

References

Affected packages

Azure Linux:3 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/azure-linux/libsoup

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.4.4-16

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92409.json"