Skip to content
Red HatCVE-2026-15713

Red Hat libsoup: denial of service

Medium5.9CVE-2026-15713 · Published Jul 14, 2026 · updated Jul 15, 2026

A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote, unauthenticated attacker acting as a malicious network peer can trick the connection engine into allocating stream states that are subsequently leaked during cleanup. Over a sustained period, this flaw allows the remote attacker to consume the system's heap allocations incrementally, triggering a denial of service (DoS) through an ultimate Out-of-Memory (OOM) application crash.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: out-of-bounds read
Medium6.5Jul 14
Red Hat Enterprise Linux 10: denial of service
Medium5.9Jul 14
Red Hat open5gs: out-of-bounds read
High8.6Jul 14
Red Hat Enterprise Linux: integer overflow
Medium4.8Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.