{"id":"AZL-92409","summary":"CVE-2026-15712 affecting package libsoup 3.4.4-16","details":"A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tracking framework. When the library processes an HTTP/2 GOAWAY frame, it improperly handles the \"Additional Debug Data\" payload by assuming the data stream is a safely NUL-terminated C-string. Because the parser lacks strict length-boundary verification before reading this data, a remote, unauthenticated attacker can intentionally send a malformed GOAWAY frame missing the appropriate null delimiter. This causes the library to read past the end of the allocated buffer, triggering an application crash that results in a denial of service (DoS), or potentially exposing fragments of memory contents.","modified":"2026-08-31T05:26:27Z","published":"2026-07-14T19:16:51Z","upstream":["CVE-2026-15712"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15712"}],"affected":[{"package":{"name":"libsoup","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libsoup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.4.4-16"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92409.json"}}],"schema_version":"1.9.0"}