SUSE Releases Patches for Libsoup and Rpcbind Vulnerabilities

SUSE Releases Patches for Libsoup and Rpcbind Vulnerabilities

First seen 10 Sep 2026, 15:20 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

SUSE has issued updates to address two vulnerabilities affecting its Linux distributions. CVE-2026-12548 involves an out-of-bounds read in libsoup's multipart body parser, while CVE-2026-16461 pertains to a stack buffer overflow in rpcbind's rpcinfo functionality. Both vulnerabilities were published on July 21, 2026, and are rated as moderate in severity. Users of SUSE Linux Enterprise Server 12 SP5 and SUSE Linux Micro 6.2 are advised to apply the patches using recommended installation methods. The vulnerabilities could potentially allow attackers to exploit the affected systems if not patched. Currently, there are no reports of active exploitation for these vulnerabilities.

Key Points: • SUSE has released patches for CVE-2026-12548 and CVE-2026-16461. • CVE-2026-12548 is an out-of-bounds read in libsoup, while CVE-2026-16461 is a stack buffer overflow in rpcbind. • Both vulnerabilities are rated moderate and require immediate patching to secure affected systems.

Ask AI about this cluster

Timeline

2026-07-21
CVE-2026-12548 and CVE-2026-16461 published
Two vulnerabilities affecting SUSE Linux distributions were disclosed, impacting libsoup and rpcbind.
Linuxsecurity
2026-09-06
Patch released for rpcbind
SUSE released an update for rpcbind addressing CVE-2026-16461, urging users to apply the patch.
Linuxsecurity
2026-09-09
Patch released for libsoup
SUSE issued an update for libsoup to fix CVE-2026-12548, recommending immediate application of the patch.
Linuxsecurity