Critical CVEs in Fedora libsoup3 Require Immediate Attention

Critical CVEs in Fedora libsoup3 Require Immediate Attention

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 60.6

Article Content

Browse articles
ThreatCluster

Fedora has released important updates for libsoup3, an HTTP library, addressing multiple critical CVEs. The vulnerabilities include CVE-2026-15712, CVE-2026-15709, CVE-2026-15711, CVE-2026-15713, and CVE-2026-15714, all published on July 14, 2026. These flaws can lead to remote denial of service attacks and buffer over-read issues, affecting systems running Fedora 43 and 44. The updates were backported by Adrian Vovk on September 5, 2026, and users are advised to apply the patches using the 'dnf' update program. The vulnerabilities pose a significant risk, as they can be exploited to disrupt services and potentially lead to system crashes. Administrators should prioritize applying these updates to mitigate risks associated with these vulnerabilities.

Key Points: • Five critical CVEs in libsoup3 require urgent patching. • Vulnerabilities can lead to remote denial of service and buffer over-read attacks. • Affected systems include Fedora 43 and 44; updates available via 'dnf'.

Ask AI about this cluster

Timeline

2026-07-14
Multiple CVEs published for libsoup3
CVE-2026-15712, CVE-2026-15709, CVE-2026-15711, CVE-2026-15713, and CVE-2026-15714 were disclosed, affecting Fedora systems.
Linuxsecurity
2026-07-14
CVE-2026-15713 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15709 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15711 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15714 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15712 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-05
Backporting of CVE fixes
Adrian Vovk backported various CVE fixes for libsoup3 in Fedora 43 and 44.
Linuxsecurity
2026-09-08
Fedora 44 libsoup3 update released
An important update was released for Fedora 44 addressing multiple CVEs in libsoup3.
Linuxsecurity
2026-09-10
Fedora 43 libsoup3 update released
An update for Fedora 43 was also released, addressing the same critical vulnerabilities.
Linuxsecurity