Amazon Linux 2023 : libsoup3, libsoup3-devel (ALAS2023-2026-3144)

high Nessus Plugin ID 351071

Synopsis

The remote Amazon Linux 2023 host is missing a security update.

Description

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2023-2026-3144 advisory.

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup- based client when max_incoming_payload_size is set to 0. (CVE-2026-12478)

SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy- Authorization headers from the previous proxy are sent to the new proxy, leaking credentials.
(CVE-2026-12547)

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application using libsoup or potentially disclose heap memory contents. (CVE-2026-12548)

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding. (CVE-2026-12549)

A heap buffer over-read vulnerability was discovered in libsoup's HTTP/2 connection tracking framework.
When the library processes an HTTP/2 GOAWAY frame, it improperly handles the Additional Debug Data payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents. (CVE-2026-15712)

A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash. (CVE-2026-15713)

An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming multipart boundary strings. When processing a crafted HTTP response containing a malformed or oversized boundary parameter, the internal stream reader reads past the allocated buffer bounds. A remote, unauthenticated attacker can exploit this behavior to cause a service denial (DoS) through application failure or potentially read fragments of unauthorized memory metadata. (CVE-2026-15714)

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure. (CVE-2026-66339)

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB. (CVE-2026-77014)

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix.

CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in soup_message_headers_get_ranges_internal() in libsoup/soup-message-headers.c, but the coalescing loop still removes merged ranges using g_array_remove_index() for each coalesced element. Because GArray is contiguous, each mid-array removal performs an O(N) memmove. When many identical satisfiable ranges are supplied (for example bytes=0-0 repeated thousands of times), the loop performs O(N2) work coalescing them into a single range.

The vulnerable path is reachable server-side from handle_partial_get() in libsoup/server/http1/soup- server-message-io-http1.c when a SoupServer handler returns HTTP 200 with a non-empty body. No authentication is required. The number of ranges is bounded only by the maximum request header size (~100 KiB), allowing roughly 25,000 ranges per request. Reporter measurements on libsoup HEAD containing the CVE-2025-32907 fix show ~90 ms single-core CPU per such request at the wire maximum, blocking the server's event loop for that duration.

This is a CPU exhaustion / availability issue only. No memory corruption or information disclosure occurs.

Affected: libsoup versions containing the CVE-2025-32907 fix but not merge request !550.Fixed upstream: MR !550 merged 2026-08-20, replacing per-element removal with O(N) in-place compaction and rejecting Range headers requesting more than 200 ranges.Upstream report:
https://gitlab.gnome.org/GNOME/libsoup/-/issues/538Related: CVE-2025-32907 (CVE-2026-77680)

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution. (CVE-2026-85197)

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session. (CVE-2026-85534)

Tenable has extracted the preceding description block directly from the tested product security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Run 'dnf update libsoup3 --releasever 2023.12.20260928' or or 'dnf update --advisory ALAS2023-2026-3144 --releasever 2023.12.20260928' to update your system.

See Also

https://alas.aws.amazon.com//AL2023/ALAS2023-2026-3144.html

https://alas.aws.amazon.com/faqs.html

https://explore.alas.aws.amazon.com/CVE-2026-12478.html

https://explore.alas.aws.amazon.com/CVE-2026-12547.html

https://explore.alas.aws.amazon.com/CVE-2026-12548.html

https://explore.alas.aws.amazon.com/CVE-2026-12549.html

https://explore.alas.aws.amazon.com/CVE-2026-15712.html

https://explore.alas.aws.amazon.com/CVE-2026-15713.html

https://explore.alas.aws.amazon.com/CVE-2026-15714.html

https://explore.alas.aws.amazon.com/CVE-2026-66339.html

https://explore.alas.aws.amazon.com/CVE-2026-77014.html

https://explore.alas.aws.amazon.com/CVE-2026-77680.html

https://explore.alas.aws.amazon.com/CVE-2026-85197.html

https://explore.alas.aws.amazon.com/CVE-2026-85534.html

Plugin Details

Severity: High

ID: 351071

File Name: al2023_ALAS2023-2026-3144.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/29/2026

Updated: 9/29/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.43

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:C

CVSS Score Source: CVE-2026-85197

CVSS v3

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:amazon:linux:2023, p-cpe:/a:amazon:linux:libsoup3-debuginfo, p-cpe:/a:amazon:linux:libsoup3-debugsource, p-cpe:/a:amazon:linux:libsoup3-devel, p-cpe:/a:amazon:linux:libsoup3-doc, p-cpe:/a:amazon:linux:libsoup3

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 6/11/2026

Reference Information

CVE: CVE-2026-12478, CVE-2026-12547, CVE-2026-12548, CVE-2026-12549, CVE-2026-15712, CVE-2026-15713, CVE-2026-15714, CVE-2026-66339, CVE-2026-77014, CVE-2026-77680, CVE-2026-85197, CVE-2026-85534

IAVA: 2026-A-0555-S, 2026-A-0894