UbuntuUpdates.org

Package "libsoup3"

Name: libsoup3

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GObject introspection data for the libsoup HTTP library
  • HTTP library implementation in C -- Shared library
  • HTTP library implementation in C -- Common files
  • HTTP library implementation in C -- Development files

Latest version: 3.6.6-1ubuntu0.1
Release: resolute (26.04)
Level: updates
Repository: main

Links



Other versions of "libsoup3" in Resolute

Repository Area Version
base main 3.6.6-1
base universe 3.6.6-1
security main 3.6.6-1ubuntu0.1
security universe 3.6.6-1ubuntu0.1
updates universe 3.6.6-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.6.6-1ubuntu0.1 2026-10-07 15:39:07 UTC

libsoup3 (3.6.6-1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Use-after-free in HTTP/2 server
    - debian/patches/CVE-2026-4271.patch: Protect message io while reading
      and writing in libsoup/server/http2/soup-server-message-io-http2.c.
    - CVE-2026-4271
  * SECURITY UPDATE: Session hijacking in HTTP negotiation
    - debian/patches/CVE-2026-5119.patch: Do not send cookies to a HTTP proxy
      for a HTTPS request in libsoup/cookies/soup-cookie-jar.c.
    - CVE-2026-5119
  * SECURITY UPDATE: Control bypass in soup_body_input_stream_read_chunked
    - debian/patches/CVE-2026-6324-1.patch: Improve parsing of chunked
      request body in libsoup/http1/soup-body-input-stream.c and
      libsoup/server/http1/soup-server-message-io-http1.c
    - debian/patches/CVE-2026-6324-post1.patch: Limit buffer read to the
      received content in libsoup/http1/soup-body-input-stream.c
    - debian/patches/CVE-2026-6324-post2.patch: Fix OOB read when parsing
      chunk size in libsoup/http1/soup-body-input-stream.c
    - debian/patches/CVE-2026-6324-post3.patch: Require chunk-size to begin
      with a hex digit in libsoup/http1/soup-body-input-stream.c
    - CVE-2026-6324
  * SECURITY UPDATE: Information disclosure via Proxy-Authorization header
    - debian/patches/CVE-2026-66339.patch: Don't send Proxy-Authorization
      through an established tunnel in libsoup/auth/soup-auth-manager.c
    - CVE-2026-66339
  * SECURITY UPDATE: Integer overflow and Denial of Service in HTTP Range
    header processing.
    - debian/patches/CVE-2026-77XXX.patch: Fix Range parsing overflows
      and coalescing cost in libsoup/soup-message-headers-private.h and
      libsoup/soup-message-headers.c
    - CVE-2026-77014
    - CVE-2026-77680
  * SECURITY UPDATE: Use-after-free in HTTP/2 client implementation
    - debian/patches/CVE-2026-85197-1.patch: Fix crash in on_data_read after
      connection is destroyed in libsoup/http2/soup-client-message-io-http2.c
    - debian/patches/CVE-2026-85197-2.patch: Keep reference to message
      cancellable in libsoup/http2/soup-client-message-io-http2.c
    - debian/patches/CVE-2026-85197-post1.patch: Fix cancellable leak in
      libsoup/http2/soup-client-message-io-http2.c
    - CVE-2026-85197
  * SECURITY UPDATE: Denial of service in libsoup
    - debian/patches/CVE-2026-85534.patch: Never send more body bytes than
      nghttp2 requested in libsoup/http2/soup-client-message-io-http2.c
    - CVE-2026-85534

 -- Kyle Kernick Wed, 30 Sep 2026 13:43:06 -0600

CVE-2026-4271 A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme
CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext
CVE-2026-6324 A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` fu
CVE-2026-66339 A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header
CVE-2026-77014 A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt
CVE-2026-77680 An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed
CVE-2026-85197 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the
CVE-2026-85534 A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the c



About   -   Send Feedback to @ubuntu_updates