Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0123-1

Опубликовано: 14 янв. 2026
Источник: suse-cvrf

Описание

Security update for libsoup

This update for libsoup fixes the following issues:

  • CVE-2025-14523: Reject duplicated Host in headers (bsc#1254876).

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
libsoup-2_4-1-2.62.2-5.23.1
libsoup-2_4-1-32bit-2.62.2-5.23.1
libsoup-devel-2.62.2-5.23.1
libsoup-lang-2.62.2-5.23.1
typelib-1_0-Soup-2_4-2.62.2-5.23.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libsoup-2_4-1-2.62.2-5.23.1
libsoup-2_4-1-32bit-2.62.2-5.23.1
libsoup-devel-2.62.2-5.23.1
libsoup-lang-2.62.2-5.23.1
typelib-1_0-Soup-2_4-2.62.2-5.23.1

Описание

A flaw in libsoup's HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libsoup-2_4-1-2.62.2-5.23.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libsoup-2_4-1-32bit-2.62.2-5.23.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libsoup-devel-2.62.2-5.23.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libsoup-lang-2.62.2-5.23.1

Ссылки