Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages.
Security Fix(es):
A flaw was found in libsoup, where the soupmultipartnewfrommessage() function is vulnerable to an out-of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds.(CVE-2025-32914)
A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overread. This can allow an attacker to potentially access sensitive information or cause an application level denial of service.(CVE-2026-2369)
{
"severity": "Critical"
}{
"x86_64": [
"libsoup3-3.4.5-16.oe2403sp1.x86_64.rpm",
"libsoup3-debuginfo-3.4.5-16.oe2403sp1.x86_64.rpm",
"libsoup3-debugsource-3.4.5-16.oe2403sp1.x86_64.rpm",
"libsoup3-devel-3.4.5-16.oe2403sp1.x86_64.rpm"
],
"src": [
"libsoup3-3.4.5-16.oe2403sp1.src.rpm"
],
"aarch64": [
"libsoup3-3.4.5-16.oe2403sp1.aarch64.rpm",
"libsoup3-debuginfo-3.4.5-16.oe2403sp1.aarch64.rpm",
"libsoup3-debugsource-3.4.5-16.oe2403sp1.aarch64.rpm",
"libsoup3-devel-3.4.5-16.oe2403sp1.aarch64.rpm"
],
"noarch": [
"libsoup3-help-3.4.5-16.oe2403sp1.noarch.rpm"
]
}