<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Libsoup (&lt;= 3.x) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/libsoup--3.x/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 18:29:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/libsoup--3.x/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Out-of-Bounds Read Vulnerability in libsoup data URI handling</title><link>https://feed.craftedsignal.io/briefs/2026-09-libsoup-data-uri-vulnerability/</link><pubDate>Tue, 29 Sep 2026 18:29:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-libsoup-data-uri-vulnerability/</guid><description>A memory corruption vulnerability in the libsoup soup_uri_decode_data_uri function allows for out-of-bounds reads or application crashes when processing crafted data URI payloads.</description><content:encoded><![CDATA[<p>A memory safety vulnerability, identified as CVE-2026-102555, exists within the libsoup library, specifically in the soup_uri_decode_data_uri() function. The library incorrectly handles base64 data-URI payloads by treating them as NUL-terminated strings during the invocation of g_base64_decode_inplace(). When a percent-decoded payload contains embedded NUL bytes, the function fails to correctly initialize the decoded length. This uninitialized length is subsequently used as the size for the returned GBytes object, leading to an out-of-bounds memory read. An attacker capable of influencing the data URIs processed by a libsoup-based application can trigger an application crash, potentially leading to a denial-of-service condition or information disclosure from the process memory space. This vulnerability impacts applications relying on libsoup for URI and network data processing on Linux environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability can result in the crash of any service or application utilizing the libsoup library to parse data URIs, causing denial-of-service. Furthermore, the out-of-bounds read may allow an attacker to access sensitive information residing in the memory adjacent to the improperly handled buffer, which could facilitate more complex exploitation in the context of the vulnerable application's privileges.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Identify all applications and services within the environment that utilize the libsoup library.</li>
<li>Monitor vendor security advisories from the GNOME project and distributions (e.g., Debian, Fedora, RHEL) for the release of patched libsoup versions.</li>
<li>Update libsoup to the vendor-provided patched version immediately upon availability.</li>
<li>Implement memory-safe coding practices in downstream applications that pass untrusted URI inputs to libsoup, including input validation and sanitization of data URI components prior to processing.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>memory-safety</category><category>vulnerability</category><category>libsoup</category><category>heap-overflow</category><category>cve</category><category>memory-corruption</category><category>linux</category></item></channel></rss>