CVE-2026-102555 libsoup 越界读取漏洞
影响攻击者可触发越界读取或导致应用崩溃
libsoup 的 soup_uri_decode_data_uri() 函数在处理 base64 编码的 data URI 时,错误地将载荷当作 NUL 结尾字符串传给 g_base64_decode_inplace()。当百分号解码后的载荷包含内嵌 NUL 字节时,解码长度可能保持未初始化状态,并被用作返回 GBytes 的大小,从而引发越界读取或应用崩溃。
影响范围
受影响版本范围暂无公开信息,涉及包含 soup_uri_decode_data_uri() 的 libsoup 版本。
漏洞详情
漏洞类型为越界读取(CWE-125)。成因是函数对 base64 data URI 载荷的长度处理不当:在存在内嵌 NUL 字节时,解码后的长度变量未被正确初始化,却被当作缓冲区大小使用。攻击者可通过构造包含内嵌 NUL 字节的恶意 data URI 触发该缺陷,导致读取超出缓冲区边界的内存或使应用崩溃。
利用条件与风险
利用前提是应用使用 libsoup 处理攻击者可控的 data URI。实战中可造成信息泄露或拒绝服务,CVSS 8.2 属高危。
修复建议
官方修复方案暂无公开信息,建议关注 libsoup 官方安全公告并及时升级到修复版本;临时缓解措施为避免处理不可信的 data URI 输入。
A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when processing a crafted data URI.