UBUNTU-CVE-2026-85197
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-85197
Summary:
Details: A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
References: https://ubuntu.com/security/CVE-2026-85197, https://www.cve.org/CVERecord?id=CVE-2026-85197, https://gitlab.gnome.org/GNOME/libsoup/-/work_items/552
Affected packages
Package
Name: libsoup3
Purl: pkg:deb/ubuntu/libsoup3?arch=source&distro=esm-apps%2Fjammy
Affected ranges
Type: ECOSYSTEM
Events:
