Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-15968

Опубликовано: 11 мая 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-15968: libsoup3 security update (MODERATE)

[3.6.5-11]

  • Add patches for CVE-2026-4271 and CVE-2026-5119

[3.6.5-10]

  • Add patch for CVE-2026-1761

[3.6.5-9]

  • Fix CVE-2026-0719

[3.6.5-8]

  • Fix CVE-2025-14523

[3.6.5-7]

  • Add patch for CVE-2025-12105

[3.6.5-6]

  • Fix integer overflow in date/time parsing

[3.6.5-5]

  • Bump revision number

[3.6.5-4]

  • Fix several CVEs

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

libsoup3

3.6.5-3.el10_1.11

libsoup3-devel

3.6.5-3.el10_1.11

libsoup3-doc

3.6.5-3.el10_1.11

Oracle Linux x86_64

libsoup3

3.6.5-3.el10_1.11

libsoup3-devel

3.6.5-3.el10_1.11

libsoup3-doc

3.6.5-3.el10_1.11

Связанные CVE

Связанные уязвимости

rocky
3 месяца назад

Moderate: libsoup3 security update

oracle-oval
16 дней назад

ELSA-2026-19143: libsoup3 security update (MODERATE)

CVSS3: 5.3
ubuntu
5 месяцев назад

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).

CVSS3: 5.3
redhat
5 месяцев назад

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).

CVSS3: 5.3
nvd
5 месяцев назад

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).