{"id":"AZL-97482","summary":"CVE-2026-77014 affecting package libsoup 3.4.4-16","details":"A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.","modified":"2026-08-31T05:26:27Z","published":"2026-08-20T09:16:48Z","upstream":["CVE-2026-77014"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77014"}],"affected":[{"package":{"name":"libsoup","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libsoup"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.4.4-16"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97482.json"}}],"schema_version":"1.9.0"}