Back Redpacketsecurity CVE Alert: CVE-2026-102559 – Red Hat
A flaw was found in libsoup. When constructing a masked WebSocket client frame for a very large outgoing payload, size values passed to GByteArray allocation APIs could be truncated while the masking routine still used the full length, causing a heap buffer overflow.
**Risk verdict:** This is a high-impact availability risk, but urgency cannot be confirmed because KEV, SSVC, PoC and EPSS data are not provided.
**Why this matters:** A successful memory-safety failure could crash an application or its process, disrupting WebSocket-dependent services; memory corruption may also have more serious consequences than the scored impact indicates. The practical risk depends on whether an attacker can influence an application to send an exceptionally large message.
**Most likely attack path:** The network attack surface is reachable with low complexity, and requires no privileges or user interaction; the scope remains within the affected application. However, the flaw is exercised while the client constructs an outgoing frame, so an attacker would generally need a way to make the application send attacker-influenced bulk data—not merely connect to it.
**Who is most exposed:** Applications and services using libsoup for WebSocket client connections are most relevant, especially those forwarding user-controlled data or handling large messages without limits. Inventory embedded and system-linked uses, not just standalone WebSocket services.
Review WebSocket client logs for unusually large outbound messages or repeated disconnects.
Monitor affected process crashes, restarts and allocator errors.
Correlate large outbound frames with user-controlled requests or upstream data.
Mitigation and prioritisation
Apply the vendor’s fixed package update as soon as available; confirm package status where applicability is uncertain.
Enforce strict outbound WebSocket message-size limits and avoid single-message bulk transfers.
Restrict or disable affected WebSocket client functionality where feasible until patched.
Test representative WebSocket workloads, then deploy through normal change controls.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
