CyberRota Analysis
AI-GeneratedA vulnerability in libsoup affects applications that utilize the WebSocket Pong frame handling, where the emitted signal incorrectly uses a GByteArray pointer instead of the expected GBytes type. This flaw can lead to heap corruption or application crashes when processing specially crafted Pong frames. Developers and security teams using libsoup in their applications should prioritize addressing this issue to mitigate potential exploitation risks.
Original NVD Description
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.