Linuxsecurity
Critical libsoup2 Vulnerability Disclosed in SUSE Update
Article Content
On September 3, 2026, SUSE released an important update addressing a critical out-of-bounds read vulnerability in libsoup2, identified as CVE-2026-12548. This flaw arises from an integer truncation in the multipart body parser, potentially allowing attackers to exploit the vulnerability. The affected systems include various SUSE Linux Enterprise products, with specific patch instructions provided for different versions. Additionally, the update includes fixes for other issues and improvements in testing procedures. The vulnerability was published on July 21, 2026, and is rated as important. Administrators are urged to apply the patches promptly to mitigate risks. The update also addresses previous CVEs, including CVE-2025-14523 and CVE-2025-46420, which were disclosed earlier.
Key Points: • CVE-2026-12548 is a critical out-of-bounds read vulnerability in libsoup2. • Affected systems include various SUSE Linux Enterprise products; patches are available. • Administrators are urged to apply the updates to mitigate potential exploitation.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.