Skip to content
Red HatCVE-2026-77014

A flaw was found in libsoup's SoupServer HTTP Range header processing

Medium5.3CVE-2026-77014 · Published Aug 20, 2026 · updated Aug 25, 2026

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat multicloud-operators-subscription: information disclosure
High7.7Aug 20
A flaw was found in the multicloud-operators-subscription component
Critical9.9Aug 20
Red Hat Advanced Cluster Management for Kubernetes 2: information disclosure
Low2.5Aug 20
Red Hat lighthouse: information disclosure
Medium5.4Aug 20
Red Hat Lighthouse. A remote attacker: privilege escalation
Low3.7Aug 20
A flaw was found in Kata Containers
High8.1Aug 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.