PT-2026-51330 · Red Hat+2 · Red Hat Enterprise Linux 10+6
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A regression occurred when a rework commit replaced specific overflow checks with a general signed comparison. This issue is triggered when a client sends a Range request with a suffix length that exceeds the content size. Because the resulting negative start value is not properly clamped, the system generates malformed HTTP 206 responses and causes log flooding.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Libsoup2.4
Libsoup3