ALSA-2026:68234

Source
https://errata.almalinux.org/9/ALSA-2026-68234.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:68234.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:68234
Related
  • CVE-2026-15709
  • CVE-2026-15711
Published
2026-09-16T00:00:00Z
Modified
2026-09-17T12:00:02Z
Summary
Moderate: libsoup security update
Details

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

  • SoupWebsocketExtensionDeflate: libsoup: libsoup: WebSocket permessage-deflate Unbounded Decompression Remote Denial of Service (CVE-2026-15709)
  • libsoup: SoupWebsocketConnection: libsoup: WebSocket remote denial of service via oversized control frame protocol violation (CVE-2026-15711)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:9 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/almalinux/libsoup

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.72.0-16.el9_8.3

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:68234.json"

AlmaLinux:9 / libsoup-devel

Package

Name
libsoup-devel
Purl
pkg:rpm/almalinux/libsoup-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.72.0-16.el9_8.3

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2026:68234.json"