CVE-2026-102556
CVE-2026-102556: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh8.6
High [CVE-2026-102556] Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion
CVE-2026-102556Source published Source updated
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong. This issue is rated Important. A remote peer can send a WebSocket Pong that reaches receive_pong(). Exploitation requires an application to connect a::pong handler that expects GBytes; many keep-alive users do. Successful triggering can crash the process or corrupt heap state. libsoup WebSocket support is used by client and server applications on Red Hat platforms. Red Hat severity: Important — CVSS 8.6…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
2 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- To mitigate avoid connecting custom handlers to SoupWebsocketConnection::pong, or avoid WebSocket use with untrusted peers.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.