Skip to content
Red HatCVE-2026-85534

Red Hat libsoup.: reachable assertion

Medium5.9CVE-2026-85534 · Published Sep 4, 2026 · updated Sep 8, 2026

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Flatpak: race condition
Medium5.8Sep 4
Red Hat libtpms: denial of service
Medium6.5Sep 4
Red Hat Enterprise Linux 10: integer overflow
Medium6.5Sep 4
Red Hat: heap buffer overflow
High7.5Sep 4
Red Hat libsoup: use after free
High7.6Sep 4
Red Hat Ansible Automation Platform 2: improper signature check
Medium5.9Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.