[CLSA-2026:1787783675] libsoup: Fix of CVE-2026-66338
Type:
security
Severity:
Important
Release date:
2026-08-26 22:35:18 UTC
Description:
- CVE-2026-66338: reject chunk sizes that violate RFC 9112 when parsing the chunked request body, preventing an HTTP request smuggling parsing differential
CVEs fixed:
Updated packages:
  • libsoup-2.72.0-10.el9_6.3.tuxcare.els9.i686.rpm
    sha:8098564d0524fb5f3c26d79e03b674ed7d1353663a7b77fca1177fe0fffb55c9
  • libsoup-2.72.0-10.el9_6.3.tuxcare.els9.x86_64.rpm
    sha:5021f53e4e3e25edb1d547a69df781cb7246790e4dfc3fe8c637408d1d1704a1
  • libsoup-devel-2.72.0-10.el9_6.3.tuxcare.els9.i686.rpm
    sha:d3e3f739182468d15d34f2c78ab34697ec7636e85021c1eeeb535ff3466c2f57
  • libsoup-devel-2.72.0-10.el9_6.3.tuxcare.els9.x86_64.rpm
    sha:6c1afbbbae053e24e49f443e2d5c4cd1c80d4b53c5839f52e77eaa1e4972400f
  • libsoup-doc-2.72.0-10.el9_6.3.tuxcare.els9.noarch.rpm
    sha:34f8caf3ab5cb7b6092ed5dbf94ed1fb0ee4cc8693898a09b46775e9ed390fa3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.