[CLSA-2026:1789383552] libsoup: Fix of 4 CVEs
Type:
security
Severity:
None
Release date:
2026-09-14 13:11:48 UTC
Description:
- Rebase onto vendor 2.56.0-6.amzn2.0.8, which fixes CVE-2026-15711 (oversized WebSocket control frames are now rejected per RFC 6455 section 5.5) - CVE-2026-5119: do not send cookies to a HTTP proxy for a HTTPS request - CVE-2026-66338: reject chunk sizes carrying trailing garbage and chunk sizes that overflow goffset instead of parsing them permissively, narrowing an HTTP request smuggling differential - CVE-2026-66337: clamp the bytes returned by soup_filter_input_stream_read_until() to the caller buffer length when the boundary is found, preventing a heap buffer over-read
Updated packages:
  • libsoup-2.56.0-6.amzn2.0.8.tuxcare.els1.i686.rpm
    sha:15f7f64b645345840e5468ba904e0998dab795a646138d666dd263b8d7d7862c
  • libsoup-2.56.0-6.amzn2.0.8.tuxcare.els1.x86_64.rpm
    sha:9528e4193e956aa8404e8db5f8ac88aa5c2a3966d622f0a6b5b5a646d4e13e01
  • libsoup-devel-2.56.0-6.amzn2.0.8.tuxcare.els1.x86_64.rpm
    sha:b4852ce87ea270b878b945caee6788fc11186ad25d39811452a35695b00b4e94
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.