A flaw was found in libsoups SoupServer. A remote attacker could exploit a use-after-free vulnerability where the soup_server_disconnect() function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server crash and a Denial of Service.
The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libsoup | Gnome | - (including) | - (including) |
| Enterprise_linux | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
| Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
| Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
| Enterprise_linux | Redhat | 10.0 (including) | 10.0 (including) |
| Libsoup2.4 | Ubuntu | esm-infra/xenial | * |
| Libsoup3 | Ubuntu | questing | * |