gpp_maybe
Security update for libsoup
SUSE-SLE-Micro-6.1-420
This update for libsoup fixes the following issues: - CVE-2025-32049: denial of service attack to websocket server (bsc#1240751). - CVE-2026-1467: lack of input sanitization can lead to unintended or unauthorized HTTP requests (bsc#1257398). - CVE-2026-1536: HTTP header injection or response splitting via CRLF injection in the Content-Disposition header (bsc#1257440). - CVE-2026-1539: proxy authentication credentials leaked via the Proxy-Authorization header when handling HTTP redirects (bsc#1257441). - CVE-2026-1760: improper handling of HTTP requests combining certain headers by SoupServer can lead to HTTP request smuggling and potential DoS (bsc#1257597). - CVE-2026-1761: incorrect length calculation when parsing of multipart HTTP responses can lead to a stack-based buffer overflow (bsc#1257598). - CVE-2026-2369: buffer overread due to integer underflow when handling zero-length resources (bsc#1258120). - CVE-2026-2443: out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers (bsc#1258170). - CVE-2026-2708: HTTP request smuggling via duplicate Content-Length headers (bsc#1258508).
-
Release DateMar 3 2026
-
ReferencesBugzilla: 1240751, 1257398, 1257440, 1257441, 1257597, 1257598, 1258120, 1258170, 1258508
CVEs: CVE-2025-32049, CVE-2026-1467, CVE-2026-1536, CVE-2026-1539, CVE-2026-1760, CVE-2026-1761, CVE-2026-2369, CVE-2026-2443, CVE-2026-2708 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Micro 6.1 aarch64
-
Packages
SUSE Linux Micro 6.1 ppc64le
-
Packages
SUSE Linux Micro 6.1 s390x
-
Packages
SUSE Linux Micro 6.1 x86_64
-
Packages