Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of http range responses
Published Aug 20, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.23%
Description
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INT_MAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 6 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 7 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 8 | affected |
| |||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
| |||
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
libsoup3
Fix deferred
Red Hat Enterprise Linux 6
libsoup
Fix deferred
Red Hat Enterprise Linux 7
gnome-clocks
Fix deferred
Red Hat Enterprise Linux 7
libsoup
Fix deferred
Red Hat Enterprise Linux 8
container-tools:rhel8/podman
Fix deferred
Red Hat Enterprise Linux 8
libsoup
Fix deferred
Red Hat Enterprise Linux 9
libsoup
Fix deferred
Red Hat Enterprise Linux 9
podman
Fix deferred
Red Hat OpenShift Container Platform 4
podman
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsoup3 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | gnome-clocks | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | container-tools:rhel8/podman | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | libsoup | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | podman | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | podman | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
No mitigation is available for this vulnerability.
Red Hat statement
An integer truncation flaw was found in libsoup's HTTP Range header processing. A remote attacker can exploit this to cause the server to silently omit requested byte ranges from responses. Exploitation requires the server to be serving resources larger than approximately 2 GB, which limits real-world impact.
Red Hat mitigation
No mitigation is available for this vulnerability.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-77014 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2520143 issue-trackingx_refsource_REDHATIssue Tracking
- https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
- https://nvd.nist.gov/vuln/detail/CVE-2026-77014
- https://www.cve.org/CVERecord?id=CVE-2026-77014
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-77014 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2520143 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-77014 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-77014 |
Change history (0)
No recorded changes yet.