Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4898 articles · 221206 vulns · 37/41 feeds (7d)
← Back to list
5.9
CVE-2026-85534EXPLOITED
red hat · red hat enterprise linux

Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read

Description

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then copies the full buffer into a smaller DATA callback without a runtime bounds check, which can abort the process or fail the HTTP/2 session.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/security/cve/CVE-2026-85534(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2528440(issue-tracking, x_refsource_REDHAT)
  • https://gitlab.gnome.org/GNOME/libsoup/-/blob/master/libsoup/http2/soup-client-message-io-http2.c
  • https://gitlab.gnome.org/GNOME/libsoup/-/work_items/551

Related News (1 articles)

Tier C
VulDB18d ago
CVE-2026-85534 | Red Hat Enterprise Linux up to 10 libsoup buffer overflow
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.9 NONE
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-617
PublishedSep 4, 2026
Last enriched18d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score2
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-94184EXP
Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01)
Trending: 59
NONECVE-2026-87766EXP
Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup
Trending: 55
NONECVE-2026-93676EXP
Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks
Trending: 49
NONECVE-2026-93558
Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserverextensionhandler leads to denial of service
Trending: 41
NONECVE-2026-93562
Io.netty/netty-codec-http: netty: incomplete validation of malformed transfer-encoding allows http request smuggling
Trending: 41

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 4, 2026
Discovered by ZDM
Sep 4, 2026
Actively Exploited
Sep 4, 2026
Exploit Available
Sep 4, 2026