gpp_maybe
Security update for libsoup2
SUSE-SLE-Micro-5.3-2026-834
This update for libsoup2 fixes the following issues: - CVE-2025-32049: denial of service attack to websocket server (bsc#1240751). - CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). - CVE-2026-1539: proxy authentication credentials leaked via the Proxy-Authorization header when handling HTTP redirects (bsc#1257441). - CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request smuggling and potential DoS (bsc#1257597). - CVE-2026-2369: buffer overread due to integer underflow when handling zero-length resources (bsc#1258120). - CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers (bsc#1258170). - CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508).
-
Release DateMar 5 2026
-
ReferencesBugzilla: 1240751, 1257398, 1257441, 1257597, 1258120, 1258170, 1258508
CVEs: CVE-2025-32049, CVE-2026-1467, CVE-2026-1539, CVE-2026-1760, CVE-2026-2369, CVE-2026-2443, CVE-2026-2708 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Micro 5.3 aarch64
-
Packageslibsoup-2_4-1
HTTP client/server library for GNOMElibsoup22.74.2-150400.3.31.1 lock rpm
HTTP client/server library for GNOME2.74.2-150400.3.31.1 lock src
SUSE Linux Enterprise Micro 5.3 s390x
-
Packageslibsoup-2_4-1
HTTP client/server library for GNOMElibsoup22.74.2-150400.3.31.1 lock rpm
HTTP client/server library for GNOME2.74.2-150400.3.31.1 lock src
SUSE Linux Enterprise Micro 5.3 x86_64
-
Packageslibsoup-2_4-1
HTTP client/server library for GNOMElibsoup22.74.2-150400.3.31.1 lock rpm
HTTP client/server library for GNOME2.74.2-150400.3.31.1 lock src