Skip to content
SUSE Important Update libsoup2 Security Flaws Remediation 2026-3936

SUSE Important Update libsoup2 Security Flaws Remediation 2026-3936

Linuxsecurity •LinuxSecurity Advisories • September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

## This update for libsoup2 fixes the following issues: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: * tld-test: update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. * Increase test timeout for all arches except x86_64 and run tests again should they fail the first time, the testsuite is flaky. * Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds. * fix an intermittent test failure (glgo#GNOME/libsoup#399). * Fix build with libxml2-2.12.0 and clang-17. * Add upstream bug fixes: * lib: Add g_task_set_source_tag() everywhere * lib: Add names to various GSources

## This update for libsoup2 fixes the following issues: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: * tld-test: update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. * Increase test timeout for all arches except x86_64 and run tests again should they fail the first time, the testsuite is flaky. * Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds. * fix an intermittent test failure (glgo#GNOME/libsoup#399). * Fix build with libxml2-2.12.0 and clang-17. * Add upstream bug fixes: * lib: Add g_task_set_source_tag() everywhere * lib: Add names to various GSources

* CVE-2025-14523 ( SUSE ): 8.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2025-14523 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

* CVE-2025-14523 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

* CVE-2025-46420 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-46420 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-46420 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2025-46421 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Announcement ID: SUSE-SU-2026:3936-1 Release Date: 2026-09-03T07:27:45Z Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities