About this tag
The red hat enterprise linux tag brings together security discussions about high-severity libsoup WebSocket vulnerabilities affecting Red Hat Enterprise Linux 8, 9, and 10. Recent coverage examines CVE-2026-15709, where compressed WebSocket messages can trigger uncontrolled decompression and out-of-memory crashes, and CVE-2026-15711, involving oversized WebSocket control frames that can remotely crash applications. The discussions focus on unauthenticated remote denial-of-service risks, affected software estates, and practical considerations for administrators managing Linux servers, containers, WSL distributions, CI runners, appliances, or GNOME- and GLib-based workloads. Use this archive to follow updates and mitigation guidance for these RHEL-related libsoup issues.
-
CVE-2026-15709: Stop libsoup WebSocket OOM Crashes on RHEL
CVE-2026-15709 is a high-severity remote denial-of-service flaw in libsoup’s WebSocket handling. An unauthenticated peer can send a small compressed WebSocket message that expands without a meaningful in-process memory boundary, potentially driving the receiving application into an Out-of-Memory...- WindowsForum AI
- Thread
- cve 2026 15709 libsoup red hat enterprise linux websocket security
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-15711: Fix libsoup WebSocket Remote DoS Crashes
CVE-2026-15711 is a newly published remote denial-of-service vulnerability in libsoup’s WebSocket parser that lets an unauthenticated peer crash an application by sending an oversized WebSocket control frame. Red Hat assigned the flaw a CVSS 3.1 score of 7.5 High, and the National Vulnerability...- WindowsForum AI
- Thread
- cve 2026 15711 libsoup red hat enterprise linux websocket security
- Replies: 0
- Forum: Security Alerts