Описание
Security update for libsoup
This update for libsoup fixes the following issue
- CVE-2026-4271: use-after-free in the HTTP/2 server when user signal handlers disconnect connections during callback execution (bsc#1259767).
Список пакетов
openSUSE Leap 16.0
libsoup-3_0-0-3.6.6-160000.2.1
libsoup-devel-3.6.6-160000.2.1
libsoup-lang-3.6.6-160000.2.1
typelib-1_0-Soup-3_0-3.6.6-160000.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1259767
- SUSE CVE CVE-2026-4271 page
Описание
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).
Затронутые продукты
openSUSE Leap 16.0:libsoup-3_0-0-3.6.6-160000.2.1
openSUSE Leap 16.0:libsoup-devel-3.6.6-160000.2.1
openSUSE Leap 16.0:libsoup-lang-3.6.6-160000.2.1
openSUSE Leap 16.0:typelib-1_0-Soup-3_0-3.6.6-160000.2.1
Ссылки
- CVE-2026-4271
- SUSE Bug 1259767