Описание
Security update for libsoup
This update for libsoup fixes the following issues
- CVE-2026-0716: out-of-bounds read when processing a crafted unmasked frame with a payload length near
UINT64_MAXsent by a WebSocket server (bsc#1256418).
Список пакетов
openSUSE Leap 16.0
libsoup-3_0-0-3.6.6-160000.3.1
libsoup-devel-3.6.6-160000.3.1
libsoup-lang-3.6.6-160000.3.1
typelib-1_0-Soup-3_0-3.6.6-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1271401
- SUSE CVE CVE-2026-12478 page
Описание
The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0.
Затронутые продукты
openSUSE Leap 16.0:libsoup-3_0-0-3.6.6-160000.3.1
openSUSE Leap 16.0:libsoup-devel-3.6.6-160000.3.1
openSUSE Leap 16.0:libsoup-lang-3.6.6-160000.3.1
openSUSE Leap 16.0:typelib-1_0-Soup-3_0-3.6.6-160000.3.1
Ссылки
- CVE-2026-12478
- SUSE Bug 1271401