Back Linuxsecurity openSUSE libsoup2 Important Out-Of-Bounds Read Vulnern 2026-3936
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
This update for libsoup2 fixes the following issues:
* CVE-2026-12548: out-of-bounds read in multipart body parser due to an
integer truncation (bsc#1272196).
Changes for libsoup2:
* tld-test: update after changes in the public suffix list: "*.bd" is no
longer in the public suffix list so let's use ".jm" instead.
* Increase test timeout for all arches except x86_64 and run tests again
should they fail the first time, the testsuite is flaky.
* Increase test timeout on s390x. The http2-body-stream test can be slow and
sometimes times out in our builds.
* fix an intermittent test failure (glgo#GNOME/libsoup#399).
* Fix build with libxml2-2.12.0 and clang-17.
* Add upstream bug fixes:
* lib: Add g_task_set_source_tag() everywhere
* lib: Add names to various GSources
* Drop no longer valid translation-update-upstream BuildRequires and macro.
* Use ldconfig_scriptlets macro for post(un) handling.
* Update to version 2.74.3:
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3936=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-3936=1
zypper in -t patch SUSE-2026-3936=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3936=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2026-3936=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3936=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3936=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-3936=1
* SUSE Linux Enterprise Micro 5.3
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
* libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1
* typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1
* libsoup2-devel-2.74.3-150400.3.40.1
* libsoup-2_4-1-2.74.3-150400.3.40.1
* libsoup2-debugsource-2.74.3-150400.3.40.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
* libsoup2-lang-2.74.3-150400.3.40.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1
* typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1
* libsoup2-devel-2.74.3-150400.3.40.1
* libsoup-2_4-1-2.74.3-150400.3.40.1
* libsoup2-debugsource-2.74.3-150400.3.40.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
* libsoup2-lang-2.74.3-150400.3.40.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
* libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1
* typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1
* libsoup2-devel-2.74.3-150400.3.40.1
* libsoup-2_4-1-2.74.3-150400.3.40.1
*
*
*
*
*
*
*
*
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
