gpp_maybe Security update for libsoup2
SUSE-SLE-Micro-5.3-2026-3936


This update for libsoup2 fixes the following issues: - CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: - tld-test: update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. - Increase test timeout for all arches except x86_64 and run tests again should they fail the first time, the testsuite is flaky. - Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds. - fix an intermittent test failure (glgo#GNOME/libsoup#399). - Fix build with libxml2-2.12.0 and clang-17. - Add upstream bug fixes: + lib: Add g_task_set_source_tag() everywhere + lib: Add names to various GSources - Drop no longer valid translation-update-upstream BuildRequires and macro. - Use ldconfig_scriptlets macro for post(un) handling. - Update to version 2.74.3: + Add missing g-i annotations to `soup_address_get_sockaddr()` and `soup_socket_read_until()`. + Add missing `extern` when building on Windows. + Update libxml2 fallback for meson wrap. + Improvements when using libsoup with meson wraps.


cloud_download Downloads

SUSE Linux Enterprise Micro 5.3 s390x
  • Packages
    libsoup-2_4-1
    HTTP client/server library for GNOME
    2.74.3-150400.3.40.1 lock rpm
    libsoup2
    HTTP client/server library for GNOME
    2.74.3-150400.3.40.1 lock src
SUSE Linux Enterprise Micro 5.3 aarch64
  • Packages
    libsoup-2_4-1
    HTTP client/server library for GNOME
    2.74.3-150400.3.40.1 lock rpm
    libsoup2
    HTTP client/server library for GNOME
    2.74.3-150400.3.40.1 lock src
SUSE Linux Enterprise Micro 5.3 x86_64
  • Packages
    libsoup-2_4-1
    HTTP client/server library for GNOME
    2.74.3-150400.3.40.1 lock rpm
    libsoup2
    HTTP client/server library for GNOME
    2.74.3-150400.3.40.1 lock src