Package "libsoup3"
| Name: |
libsoup3
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- GObject introspection data for the libsoup HTTP library
- HTTP library implementation in C -- Shared library
- HTTP library implementation in C -- Common files
- HTTP library implementation in C -- API Reference
|
| Latest version: |
3.4.4-5ubuntu0.9 |
| Release: |
noble (24.04) |
| Level: |
security |
| Repository: |
main |
Links
Other versions of "libsoup3" in Noble
Packages in group
Deleted packages are displayed in grey.
Changelog
|
libsoup3 (3.4.4-5ubuntu0.9) noble-security; urgency=medium
* SECURITY UPDATE: Use-after-free in HTTP/2 server
- debian/patches/CVE-2026-4271.patch: Protect message io while reading
and writing in libsoup/server/http2/soup-server-message-io-http2.c.
- CVE-2026-4271
* SECURITY UPDATE: Session hijacking in HTTP negotiation
- debian/patches/CVE-2026-5119.patch: Do not send cookies to a HTTP proxy
for a HTTPS request in libsoup/cookies/soup-cookie-jar.c.
- CVE-2026-5119
* SECURITY UPDATE: Control bypass in soup_body_input_stream_read_chunked
- debian/patches/CVE-2026-6324-pre1.patch: Close the connection after
responding to a request containing both Content-Length and
Transfer-Encoding in libsoup/server/http1/soup-server-message-io-http1.c
- debian/patches/CVE-2026-6324-1.patch: Improve parsing of chunked
request body in libsoup/http1/soup-body-input-stream.c and
libsoup/server/http1/soup-server-message-io-http1.c
- debian/patches/CVE-2026-6324-post1.patch: Limit buffer read to the
received content in libsoup/http1/soup-body-input-stream.c
- debian/patches/CVE-2026-6324-post2.patch: Fix OOB read when parsing
chunk size in libsoup/http1/soup-body-input-stream.c
- debian/patches/CVE-2026-6324-post3.patch: Require chunk-size to begin
with a hex digit in libsoup/http1/soup-body-input-stream.c
- CVE-2026-6324
* SECURITY UPDATE: Information disclosure via Proxy-Authorization header
- debian/patches/CVE-2026-66339.patch: Don't send Proxy-Authorization
through an established tunnel in libsoup/auth/soup-auth-manager.c
- CVE-2026-66339
* SECURITY UPDATE: Integer overflow and Denial of Service in HTTP Range
header processing.
- debian/patches/CVE-2026-77XXX.patch: Fix Range parsing overflows
and coalescing cost in libsoup/soup-message-headers-private.h and
libsoup/soup-message-headers.c
- CVE-2026-77014
- CVE-2026-77680
* SECURITY UPDATE: Use-after-free in HTTP/2 client implementation
- debian/patches/CVE-2026-85197-1.patch: Fix crash in on_data_read after
connection is destroyed in libsoup/http2/soup-client-message-io-http2.c
- debian/patches/CVE-2026-85197-2.patch: Keep reference to message
cancellable in libsoup/http2/soup-client-message-io-http2.c
- debian/patches/CVE-2026-85197-post1.patch: Fix cancellable leak in
libsoup/http2/soup-client-message-io-http2.c
- CVE-2026-85197
* SECURITY UPDATE: Denial of service in libsoup
- debian/patches/CVE-2026-85534.patch: Never send more body bytes than
nghttp2 requested in libsoup/http2/soup-client-message-io-http2.c
- CVE-2026-85534
-- Kyle Kernick Wed, 30 Sep 2026 13:59:51 -0600
|
| Source diff to previous version |
| CVE-2026-4271 |
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme |
| CVE-2026-5119 |
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext |
| CVE-2026-6324 |
A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` fu |
| CVE-2026-66339 |
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header |
| CVE-2026-77014 |
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt |
| CVE-2026-77680 |
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed |
| CVE-2026-85197 |
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the |
| CVE-2026-85534 |
A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the c |
|
|
libsoup3 (3.4.4-5ubuntu0.8) noble-security; urgency=medium
* SECURITY UPDATE: HTTP Request smuggling vulnerability
- debian/patches/CVE-2026-1801.patch: Use CRLF as line boundary when
parsing chunked encoding data in libsoup/http1/soup-body-input-
stream.c and tests/server-test.c.
- CVE-2026-1801
-- Kyle Kernick Tue, 15 Sep 2026 12:32:01 -0600
|
| Source diff to previous version |
| CVE-2026-1801 |
A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so |
|
|
libsoup3 (3.4.4-5ubuntu0.7) noble-security; urgency=medium
* SECURITY UPDATE: Carriage Return Line Feed Injection
- debian/patches/CVE-2026-1467.patch: Do host validation when checking if
a GUri is valid
- debian/patches/CVE-2026-1536-pre1.patch: Reject duplicate host headers
- debian/patches/CVE-2026-1536.patch: Always validate the headers value
when coming from untrusted source
- CVE-2026-1467
- CVE-2026-1536
* SECURITY UPDATE: Information Leak
- debian/patches/CVE-2026-1539.patch: Also remove Proxy-Authorization
header on cross origin redirect
- CVE-2026-1539
-- Bruce Cable <email address hidden> Mon, 02 Feb 2026 15:38:57 +1100
|
| Source diff to previous version |
| CVE-2026-1467 |
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP pro |
| CVE-2026-1536 |
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) seq |
| CVE-2026-1539 |
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTT |
|
|
libsoup3 (3.4.4-5ubuntu0.6) noble-security; urgency=medium
* SECURITY UPDATE: Use after free in HTTP/2 queues.
- debian/patches/CVE-2025-12105.patch: Add SOUP_MESSAGE_FINISHED checks in
libsoup/soup-session.c.
- CVE-2025-12105
-- Hlib Korzhynskyy <email address hidden> Thu, 11 Dec 2025 17:37:16 -0330
|
| Source diff to previous version |
| CVE-2025-12105 |
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP |
|
|
libsoup3 (3.4.4-5ubuntu0.5) noble-security; urgency=medium
* SECURITY UPDATE: Denial of service.
- debian/patches/CVE-2025-32907-*.patch: Add i-- in
libsoup/soup-message-headers.c. Add B_SANITIZE_OPTION to meson.build.
- debian/patches/CVE-2025-4948.patch: Add ternary end - 2 - split check in
libsoup/soup-multipart.c.
- CVE-2025-32907
- CVE-2025-4948
* SECURITY UPDATE: Out of bounds read.
- debian/patches/CVE-2025-4969.patch: Add extra if checks for start of line
in libsoup/soup-multipart.c.
- CVE-2025-4969
* SECURITY UPDATE: Improper validation of cookie expiration.
- debian/patches/CVE-2025-4945-*.patch: Add extra date checks in
libsoup/soup-date-utils.c.
- CVE-2025-4945
-- Hlib Korzhynskyy <email address hidden> Mon, 14 Jul 2025 16:35:26 -0230
|
| CVE-2025-32907 |
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious c |
| CVE-2025-4948 |
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other application |
| CVE-2025-4969 |
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. Th |
| CVE-2025-4945 |
A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises whe |
|
About
-
Send Feedback to @ubuntu_updates