Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20845-1

Опубликовано: 29 мая 2026
Источник: suse-cvrf

Описание

Security update for libsoup

This update for libsoup fixes the following issue

  • CVE-2026-4271: use-after-free in the HTTP/2 server when user signal handlers disconnect connections during callback execution (bsc#1259767).

Список пакетов

openSUSE Leap 16.0
libsoup-3_0-0-3.6.6-160000.2.1
libsoup-devel-3.6.6-160000.2.1
libsoup-lang-3.6.6-160000.2.1
typelib-1_0-Soup-3_0-3.6.6-160000.2.1

Описание

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).


Затронутые продукты
openSUSE Leap 16.0:libsoup-3_0-0-3.6.6-160000.2.1
openSUSE Leap 16.0:libsoup-devel-3.6.6-160000.2.1
openSUSE Leap 16.0:libsoup-lang-3.6.6-160000.2.1
openSUSE Leap 16.0:typelib-1_0-Soup-3_0-3.6.6-160000.2.1

Ссылки