Opened 8 months ago

Closed 7 months ago

#22811 closed enhancement (fixed)

libsoup3-3.6.6

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (7)

comment:1 by Bruce Dubbs, 8 months ago

Milestone: 13.1 → 13.0

comment:2 by Xi Ruoyao, 8 months ago

All contents of our security patch should be already merged in this release.

comment:3 by Douglas R. Reno, 8 months ago

I suspect some additional security fixes are probably present in this as well, I'll monitor ​https://gitlab.gnome.org/Teams/Releng/security/-/wikis/2025 and the 2026 page for libsoup

comment:4 by Douglas R. Reno, 8 months ago

I just dug through everything and here's what I came up with (note that these are additional security fixes on top of the ones we have in our patch)

  • CVE-2025-9901: 5.9 Medium. In some cases, libsoup can incorrectly use cached data across different requests, potentially exposing sensitive user information
  • CVE-2025-11021: 7.5 High. An out of bounds read can occur when processing cookies with specially crafted expiration dates, leading to unintended disclosure of memory contents and possibly exposing sensitive information from the process using libsoup
  • CVE-2025-14523: 8.2 High. Possible request smuggling attacks, cache poisoning, or access control bypasses
  • CVE-2026-0716: 4.8 Medium. Unintentional memory disclosure or a crash if using a specific WebSockets configuration
  • CVE-2026-1760: 5.3 Medium. HTTP request smuggling attack, which can be performed by an unauthenticated remote attacker
  • CVE-2026-1801: 5.3 Medium. HTTP request smuggling attack leading to information disclosure
  • CVE-2026-1761: 8.6 High. Stack buffer overflow leading to unauthenticated remote code execution that requires no user interaction.
  • CVE-2026-2436: Unknown rating, but: Possible remote code execution or remotely exploitable crash due to a use after free issue (see issue #501 upstream)
  • CVE-2026-1536: 5.8 Medium. HTTP header injection or HTTP response splitting without requiring authentication or user interaction.
  • CVE-2026-2443: 5.3 Medium. In some specific configurations, this could allow a remote attacker to access portions of server memory beyond the intended response
  • CVE-2026-1467: 5.8 Medium. CRLF injection, allowing for additional HTTP headers or complete HTTP request bodies to be injected into a response stream.
  • CVE-2026-2369: Unknown on the rating, but we know it is an Integer overflow vulnerability related to a previous vulnerability fix from 3.6.1.

Note that CVE-2026-1539 is fixed upstream but did not make it into the release in time. This one can allow for sensitive proxy credentials to be leaked to other servers.

comment:5 by Douglas R. Reno, 8 months ago

Priority: normal → high

comment:6 by Douglas R. Reno, 8 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:7 by Douglas R. Reno, 7 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at b0001f44847328d4205cb3adb3de0e911b830043

SA-12.4-101 issued

Note: See TracTickets for help on using tickets.