Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97482.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97482
Upstream
  • CVE-2026-77014
Published
2026-08-20T09:16:48Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-77014 affecting package libsoup 3.4.4-16
Details

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sortranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INTMAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

References

Affected packages

Azure Linux:3 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/azure-linux/libsoup

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.4.4-16

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97482.json"