VDB
CVE-2026-85197
CVE-2026-85197
PUBLISHED
CVSS 7.6 HIGH
Reported by redhat · Published September 4, 2026
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in information disclosure or arbitrary code execution.
Risk Scores
CVSS 3.1
7.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.6.5-3.el10_2.14 |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.6.5-3.el10_2.14 |
| Red Hat | Red Hat Enterprise Linux 6 |
Timeline
- Sep 4, 2026 EPSS Score
- Sep 4, 2026 Coalition ESS Score
- Sep 4, 2026 CVE Published
- Sep 5, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 CVE Updated
- Sep 17, 2026 EPSS Score
- Sep 17, 2026 Distribution Patch
- Sep 17, 2026 Security Advisory
- Sep 18, 2026 EPSS Score
References
- RHSA-2026:68235 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2528425 issue-trackingx_refsource_REDHAT