Critical libsoup2 Vulnerability Disclosed in SUSE Update

Critical libsoup2 Vulnerability Disclosed in SUSE Update

First seen 3 Sep 2026, 18:12 UTC Linuxsecurity 60.6

Article Content

Browse articles
ThreatCluster

On September 3, 2026, SUSE released an important update addressing a critical out-of-bounds read vulnerability in libsoup2, identified as CVE-2026-12548. This flaw arises from an integer truncation in the multipart body parser, potentially allowing attackers to exploit the vulnerability. The affected systems include various SUSE Linux Enterprise products, with specific patch instructions provided for different versions. Additionally, the update includes fixes for other issues and improvements in testing procedures. The vulnerability was published on July 21, 2026, and is rated as important. Administrators are urged to apply the patches promptly to mitigate risks. The update also addresses previous CVEs, including CVE-2025-14523 and CVE-2025-46420, which were disclosed earlier.

Key Points: • CVE-2026-12548 is a critical out-of-bounds read vulnerability in libsoup2. • Affected systems include various SUSE Linux Enterprise products; patches are available. • Administrators are urged to apply the updates to mitigate potential exploitation.

Timeline

2025-04-24
CVE-2025-46420 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-04-24
CVE-2025-46421 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-11
CVE-2025-14523 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-21
CVE-2026-12548 published
An out-of-bounds read vulnerability in libsoup2 was disclosed, affecting multiple SUSE products.
Linuxsecurity
2026-09-03
SUSE releases important update for libsoup2
SUSE issued a security update addressing CVE-2026-12548 and other issues, urging immediate patching.
Linuxsecurity