PT-2026-51330 · Red Hat+2 · Red Hat Enterprise Linux 10+6

·

CVE-2026-12549

·

Published

2026-06-22

·

Updated

2026-06-22

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description A regression occurred when a rework commit replaced specific overflow checks with a general signed comparison. This issue is triggered when a client sends a Range request with a suffix length that exceeds the content size. Because the resulting negative start value is not properly clamped, the system generates malformed HTTP 206 responses and causes log flooding.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12549

Affected Products

Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Libsoup2.4
Libsoup3