CVE-2019-17266: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
- Gnome Libsoup: from 2.65.1, before 2.66.4 (fixed in 2.66.4); from 2.67.1, up to and including 2.68.1
Published 2019-10-06. Last modified 2026-06-17.