OESA-2026-3690

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3690
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3690.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3690
Upstream
  • CVE-2026-12548
  • CVE-2026-12549
  • CVE-2026-66338
  • CVE-2026-77014
  • CVE-2026-77680
Published
2026-09-05T15:03:58Z
Modified
2026-09-05T15:16:38.127170704Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
libsoup security update
Details

libsoup is an HTTP client/server library for GNOME. It uses GObjects and the glib main loop, to integrate well with GNOME applications, and also has a synchronous API, for use in threaded applications.

Security Fix(es):

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soupheadersparse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application using libsoup or potentially disclose heap memory contents.(CVE-2026-12548)

The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.(CVE-2026-12549)

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.(CVE-2026-66338)

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sortranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping the sign for range offsets differing by more than INTMAX. This causes silent omission of requested byte ranges from HTTP 206 Partial Content responses on resources larger than approximately 2 GB.(CVE-2026-77014)

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in soupmessageheadersgetrangesinternal() in libsoup/soup-message-headers.c, but the coalescing loop still removes merged ranges using garrayremoveindex() for each coalesced element. Because GArray is contiguous, each mid-array removal performs an O(N) memmove. When many identical satisfiable ranges are supplied (for example bytes=0-0 repeated thousands of times), the loop performs O(N²) work coalescing them into a single range. The vulnerable path is reachable server-side from handlepartialget() in libsoup/server/http1/soup-server-message-io-http1.c when a SoupServer handler returns HTTP 200 with a non-empty body. No authentication is required. The number of ranges is bounded only by the maximum request header size (~100 KiB), allowing roughly 25,000 ranges per request. This is a CPU exhaustion / availability issue only. No memory corruption or information disclosure occurs.(CVE-2026-77680)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / libsoup

Package

Name
libsoup
Purl
pkg:rpm/openEuler/libsoup&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.74.2-22.oe2203sp4

Ecosystem specific

{
    "src": [
        "libsoup-2.74.2-22.oe2203sp4.src.rpm"
    ],
    "x86_64": [
        "libsoup-2.74.2-22.oe2203sp4.x86_64.rpm",
        "libsoup-debuginfo-2.74.2-22.oe2203sp4.x86_64.rpm",
        "libsoup-debugsource-2.74.2-22.oe2203sp4.x86_64.rpm",
        "libsoup-devel-2.74.2-22.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "libsoup-2.74.2-22.oe2203sp4.aarch64.rpm",
        "libsoup-debuginfo-2.74.2-22.oe2203sp4.aarch64.rpm",
        "libsoup-debugsource-2.74.2-22.oe2203sp4.aarch64.rpm",
        "libsoup-devel-2.74.2-22.oe2203sp4.aarch64.rpm"
    ],
    "noarch": [
        "libsoup-help-2.74.2-22.oe2203sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3690.json"