CVE-2026-12549: fallo de gravedad media en Red Hat Enterprise Linux 10
Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.8epss 0.4%
probabilidad de explotación
0.4%top 73% de las CVE
explotación observada
noninguna fuente lo reporta
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Productos afectados
Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 6Red Hat · Red Hat Enterprise Linux 7Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9CVEs relacionadas — Red Hat Enterprise Linux 10
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-4911HIGHGlibc: buffer overflow in ld.so leading to privilege escalationEPSS 63.8%KEVCVE-2024-6387HIGHOpenssh: regresshion - race condition in ssh allows rce/dosEPSS 99.5%CVE-2023-46847HIGHSquid: denial of service in http digest authenticationEPSS 88.4%CVE-2024-3094CRITICALXz: malicious code in distributed sourceEPSS 86.0%CVE-2024-12084CRITICALRsync: heap buffer overflow in rsync due to improper checksum length handlingEPSS 72.1%CVE-2023-1183MEDIUMArbitrary file writeEPSS 64.6%