Release date:
2026-08-26 22:16:54 UTC
Description:
- CVE-2026-66338: reject chunk sizes carrying trailing garbage and chunk sizes
that overflow goffset instead of parsing them permissively, narrowing an HTTP
request smuggling differential
- CVE-2026-66337: clamp the bytes returned by soup_filter_input_stream_read_until()
to the caller buffer length when the boundary is found, preventing a heap
buffer over-read
Updated packages:
-
libsoup-2.56.0-6.amzn2.0.7.tuxcare.els2.i686.rpm
sha:1247826b1df2be9ad577797d87c7963550a400da500c0725940d5ebd16c405ce
-
libsoup-2.56.0-6.amzn2.0.7.tuxcare.els2.x86_64.rpm
sha:7affb8147f2e91013eb0bb048ce3c90a1fe240368c855c02974d126bdead0e6a
-
libsoup-devel-2.56.0-6.amzn2.0.7.tuxcare.els2.x86_64.rpm
sha:825675d49d76fb0bb2f497739fe2476c1df0ad7cb90f7a46f07694f36ac9cd25
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.