[CLSA-2026:1787782584] libsoup: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-26 22:16:54 UTC
Description:
- CVE-2026-66338: reject chunk sizes carrying trailing garbage and chunk sizes that overflow goffset instead of parsing them permissively, narrowing an HTTP request smuggling differential - CVE-2026-66337: clamp the bytes returned by soup_filter_input_stream_read_until() to the caller buffer length when the boundary is found, preventing a heap buffer over-read
Updated packages:
  • libsoup-2.56.0-6.amzn2.0.7.tuxcare.els2.i686.rpm
    sha:1247826b1df2be9ad577797d87c7963550a400da500c0725940d5ebd16c405ce
  • libsoup-2.56.0-6.amzn2.0.7.tuxcare.els2.x86_64.rpm
    sha:7affb8147f2e91013eb0bb048ce3c90a1fe240368c855c02974d126bdead0e6a
  • libsoup-devel-2.56.0-6.amzn2.0.7.tuxcare.els2.x86_64.rpm
    sha:825675d49d76fb0bb2f497739fe2476c1df0ad7cb90f7a46f07694f36ac9cd25
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.