A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
History

Fri, 04 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
References

Fri, 04 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 04 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
Title Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-416
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-09-04T07:34:31.869Z

Updated: 2026-09-04T18:15:28.916Z

Reserved: 2026-09-03T12:45:28.161Z

Link: CVE-2026-85197

cve-icon Vulnrichment

Updated: 2026-09-04T18:15:24.901Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T08:17:16.677

Modified: 2026-09-08T19:08:15.590

Link: CVE-2026-85197

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-03T13:00:00Z

Links: CVE-2026-85197 - Bugzilla