UbuntuUpdates.org

Package "libsoup3"

Name: libsoup3

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GObject introspection data for the libsoup HTTP library
  • HTTP library implementation in C -- Shared library
  • HTTP library implementation in C -- Common files
  • HTTP library implementation in C -- API Reference

Latest version: 3.4.4-5ubuntu0.9
Release: noble (24.04)
Level: security
Repository: main

Links



Other versions of "libsoup3" in Noble

Repository Area Version
base universe 3.4.4-5build2
base main 3.4.4-5build2
security universe 3.4.4-5ubuntu0.9
updates main 3.4.4-5ubuntu0.9
updates universe 3.4.4-5ubuntu0.9

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.4.4-5ubuntu0.9 2026-10-07 15:38:18 UTC

libsoup3 (3.4.4-5ubuntu0.9) noble-security; urgency=medium

  * SECURITY UPDATE: Use-after-free in HTTP/2 server
    - debian/patches/CVE-2026-4271.patch: Protect message io while reading
      and writing in libsoup/server/http2/soup-server-message-io-http2.c.
    - CVE-2026-4271
  * SECURITY UPDATE: Session hijacking in HTTP negotiation
    - debian/patches/CVE-2026-5119.patch: Do not send cookies to a HTTP proxy
      for a HTTPS request in libsoup/cookies/soup-cookie-jar.c.
    - CVE-2026-5119
  * SECURITY UPDATE: Control bypass in soup_body_input_stream_read_chunked
    - debian/patches/CVE-2026-6324-pre1.patch: Close the connection after
      responding to a request containing both Content-Length and
      Transfer-Encoding in libsoup/server/http1/soup-server-message-io-http1.c
    - debian/patches/CVE-2026-6324-1.patch: Improve parsing of chunked
      request body in libsoup/http1/soup-body-input-stream.c and
      libsoup/server/http1/soup-server-message-io-http1.c
    - debian/patches/CVE-2026-6324-post1.patch: Limit buffer read to the
      received content in libsoup/http1/soup-body-input-stream.c
    - debian/patches/CVE-2026-6324-post2.patch: Fix OOB read when parsing
      chunk size in libsoup/http1/soup-body-input-stream.c
    - debian/patches/CVE-2026-6324-post3.patch: Require chunk-size to begin
      with a hex digit in libsoup/http1/soup-body-input-stream.c
    - CVE-2026-6324
  * SECURITY UPDATE: Information disclosure via Proxy-Authorization header
    - debian/patches/CVE-2026-66339.patch: Don't send Proxy-Authorization
      through an established tunnel in libsoup/auth/soup-auth-manager.c
    - CVE-2026-66339
  * SECURITY UPDATE: Integer overflow and Denial of Service in HTTP Range
    header processing.
    - debian/patches/CVE-2026-77XXX.patch: Fix Range parsing overflows
      and coalescing cost in libsoup/soup-message-headers-private.h and
      libsoup/soup-message-headers.c
    - CVE-2026-77014
    - CVE-2026-77680
  * SECURITY UPDATE: Use-after-free in HTTP/2 client implementation
    - debian/patches/CVE-2026-85197-1.patch: Fix crash in on_data_read after
      connection is destroyed in libsoup/http2/soup-client-message-io-http2.c
    - debian/patches/CVE-2026-85197-2.patch: Keep reference to message
      cancellable in libsoup/http2/soup-client-message-io-http2.c
    - debian/patches/CVE-2026-85197-post1.patch: Fix cancellable leak in
      libsoup/http2/soup-client-message-io-http2.c
    - CVE-2026-85197
  * SECURITY UPDATE: Denial of service in libsoup
    - debian/patches/CVE-2026-85534.patch: Never send more body bytes than
      nghttp2 requested in libsoup/http2/soup-client-message-io-http2.c
    - CVE-2026-85534

 -- Kyle Kernick Wed, 30 Sep 2026 13:59:51 -0600

Source diff to previous version
CVE-2026-4271 A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme
CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext
CVE-2026-6324 A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` fu
CVE-2026-66339 A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header
CVE-2026-77014 A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt
CVE-2026-77680 An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed
CVE-2026-85197 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the
CVE-2026-85534 A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the c

Version: 3.4.4-5ubuntu0.8 2026-09-17 17:07:39 UTC

libsoup3 (3.4.4-5ubuntu0.8) noble-security; urgency=medium

  * SECURITY UPDATE: HTTP Request smuggling vulnerability
    - debian/patches/CVE-2026-1801.patch: Use CRLF as line boundary when
      parsing chunked encoding data in libsoup/http1/soup-body-input-
      stream.c and tests/server-test.c.
    - CVE-2026-1801

 -- Kyle Kernick Tue, 15 Sep 2026 12:32:01 -0600

Source diff to previous version
CVE-2026-1801 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so

Version: 3.4.4-5ubuntu0.7 2026-02-09 00:08:24 UTC

  libsoup3 (3.4.4-5ubuntu0.7) noble-security; urgency=medium

  * SECURITY UPDATE: Carriage Return Line Feed Injection
    - debian/patches/CVE-2026-1467.patch: Do host validation when checking if
      a GUri is valid
    - debian/patches/CVE-2026-1536-pre1.patch: Reject duplicate host headers
    - debian/patches/CVE-2026-1536.patch: Always validate the headers value
      when coming from untrusted source
    - CVE-2026-1467
    - CVE-2026-1536
  * SECURITY UPDATE: Information Leak
    - debian/patches/CVE-2026-1539.patch: Also remove Proxy-Authorization
      header on cross origin redirect
    - CVE-2026-1539

 -- Bruce Cable <email address hidden> Mon, 02 Feb 2026 15:38:57 +1100

Source diff to previous version
CVE-2026-1467 A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP pro
CVE-2026-1536 A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) seq
CVE-2026-1539 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTT

Version: 3.4.4-5ubuntu0.6 2025-12-15 18:18:17 UTC

  libsoup3 (3.4.4-5ubuntu0.6) noble-security; urgency=medium

  * SECURITY UPDATE: Use after free in HTTP/2 queues.
    - debian/patches/CVE-2025-12105.patch: Add SOUP_MESSAGE_FINISHED checks in
      libsoup/soup-session.c.
    - CVE-2025-12105

 -- Hlib Korzhynskyy <email address hidden> Thu, 11 Dec 2025 17:37:16 -0330

Source diff to previous version
CVE-2025-12105 A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP

Version: 3.4.4-5ubuntu0.5 2025-07-17 16:07:33 UTC

  libsoup3 (3.4.4-5ubuntu0.5) noble-security; urgency=medium

  * SECURITY UPDATE: Denial of service.
    - debian/patches/CVE-2025-32907-*.patch: Add i-- in
      libsoup/soup-message-headers.c. Add B_SANITIZE_OPTION to meson.build.
    - debian/patches/CVE-2025-4948.patch: Add ternary end - 2 - split check in
      libsoup/soup-multipart.c.
    - CVE-2025-32907
    - CVE-2025-4948
  * SECURITY UPDATE: Out of bounds read.
    - debian/patches/CVE-2025-4969.patch: Add extra if checks for start of line
      in libsoup/soup-multipart.c.
    - CVE-2025-4969
  * SECURITY UPDATE: Improper validation of cookie expiration.
    - debian/patches/CVE-2025-4945-*.patch: Add extra date checks in
      libsoup/soup-date-utils.c.
    - CVE-2025-4945

 -- Hlib Korzhynskyy <email address hidden> Mon, 14 Jul 2025 16:35:26 -0230

CVE-2025-32907 A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious c
CVE-2025-4948 A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other application
CVE-2025-4969 A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. Th
CVE-2025-4945 A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises whe



About   -   Send Feedback to @ubuntu_updates