Back Linuxsecurity SUSE Important Update libsoup2 Security Flaws Remediation 2026-3936
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
## This update for libsoup2 fixes the following issues: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: * tld-test: update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. * Increase test timeout for all arches except x86_64 and run tests again should they fail the first time, the testsuite is flaky. * Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds. * fix an intermittent test failure (glgo#GNOME/libsoup#399). * Fix build with libxml2-2.12.0 and clang-17. * Add upstream bug fixes: * lib: Add g_task_set_source_tag() everywhere * lib: Add names to various GSources
## This update for libsoup2 fixes the following issues: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: * tld-test: update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. * Increase test timeout for all arches except x86_64 and run tests again should they fail the first time, the testsuite is flaky. * Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds. * fix an intermittent test failure (glgo#GNOME/libsoup#399). * Fix build with libxml2-2.12.0 and clang-17. * Add upstream bug fixes: * lib: Add g_task_set_source_tag() everywhere * lib: Add names to various GSources
* CVE-2025-14523 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2025-14523 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-14523 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2025-46420 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-46420 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2025-46420 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2025-46421 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Announcement ID: SUSE-SU-2026:3936-1 Release Date: 2026-09-03T07:27:45Z Rating: important
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
