Описание
Security update for uriparser
This update for uriparser fixes the following issues
- CVE-2026-42371: numeric truncation in text range comparison when an application accepts URIs with a length in gigabytes (bsc#1262999).
- CVE-2026-44927: truncation of
ptrdiff_ttointin various places (bsc#1264578). - CVE-2026-44928: function family
EqualsUrican misclassify two unequal URIs as equal (bsc#1264579).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
liburiparser1-0.8.5-150000.3.14.1
uriparser-0.8.5-150000.3.14.1
uriparser-devel-0.8.5-150000.3.14.1
Ссылки
- Link for SUSE-SU-2026:3021-1
- E-Mail link for SUSE-SU-2026:3021-1
- SUSE Security Ratings
- SUSE Bug 1262999
- SUSE Bug 1264578
- SUSE Bug 1264579
- SUSE CVE CVE-2026-42371 page
- SUSE CVE CVE-2026-44927 page
- SUSE CVE CVE-2026-44928 page
Описание
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:liburiparser1-0.8.5-150000.3.14.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:uriparser-0.8.5-150000.3.14.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:uriparser-devel-0.8.5-150000.3.14.1
Ссылки
- CVE-2026-42371
- SUSE Bug 1262999
Описание
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:liburiparser1-0.8.5-150000.3.14.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:uriparser-0.8.5-150000.3.14.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:uriparser-devel-0.8.5-150000.3.14.1
Ссылки
- CVE-2026-44927
- SUSE Bug 1264578
Описание
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:liburiparser1-0.8.5-150000.3.14.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:uriparser-0.8.5-150000.3.14.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:uriparser-devel-0.8.5-150000.3.14.1
Ссылки
- CVE-2026-44928
- SUSE Bug 1264579