It looks like the cause is the HTTP chunk handling. Testing of this code showed a couple of buffer overruns, which are now fixed in snapd-glib 1.40.
** Also affects: gnome-software (Ubuntu Cosmic) Importance: Medium Status: Confirmed ** Also affects: gnome-software (Ubuntu Bionic) Importance: Undecided Status: New ** Changed in: gnome-software (Ubuntu Cosmic) Status: Confirmed => Fix Committed ** Changed in: gnome-software (Ubuntu Bionic) Status: New => Triaged ** Changed in: gnome-software (Ubuntu Bionic) Importance: Undecided => High ** Changed in: gnome-software (Ubuntu Cosmic) Importance: Medium => High ** Changed in: gnome-software (Ubuntu Cosmic) Assignee: (unassigned) => Robert Ancell (robert-ancell) ** Changed in: gnome-software (Ubuntu Bionic) Assignee: (unassigned) => Robert Ancell (robert-ancell) ** Changed in: gnome-software (Ubuntu Bionic) Status: Triaged => In Progress -- You received this bug notification because you are a member of Desktop Packages, which is subscribed to gnome-software in Ubuntu. https://bugs.launchpad.net/bugs/1740865 Title: gnome-software (5) g_realloc → g_array_maybe_expand → g_array_set_size → g_byte_array_set_size → read_cb Status in snapd-glib package in Ubuntu: Fix Committed Status in snapd-glib source package in Bionic: In Progress Status in snapd-glib source package in Cosmic: Fix Committed Bug description: The Ubuntu Error Tracker has been receiving reports about a problem regarding gnome-software. This problem was most recently seen with package version 3.26.3-2ubuntu1, the problem page at https://errors.ubuntu.com/problem/d94c431d27115bab216f9e1ea756f876e7cd933b contains more details, including versions of packages affected, stacktrace or traceback, and individual crash reports. If you do not have access to the Ubuntu Error Tracker and are a software developer, you can request it at http://forms.canonical.com/reports/. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/snapd-glib/+bug/1740865/+subscriptions -- Mailing list: https://launchpad.net/~desktop-packages Post to : desktop-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~desktop-packages More help : https://help.launchpad.net/ListHelp