openSUSE-SU-2026:21062-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21062-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21062-1
Upstream
CVE (2)
Related
Published
2026-06-26T07:23:30Z
Modified
2026-06-30T18:24:38Z
Summary
Security update for capnproto
Details

This update for capnproto fixes the following issues:

Update to version 1.4.0.

Security issues fixed:

  • CVE-2026-32239: negative Content-Length conversion treated as impossibly large length by KJ-HTTP can lead to HTTP smuggling (bsc#1259638).
  • CVE-2026-32240: integer overflow when KJ-HTTP Transfer-Encoding chunk size is parsed to a value of 2^64 or larger can lead to HTTP smuggling (bsc#1259639).

Other updates and bugfixes:

  • Have stdcoro use ::std namespace.
  • Disable stack check when HWASan is used.
  • Fix benign buffer overrun in async readMessage().
  • Shared library naming changes from libsomething-%{version}.so to libsomething.so.%{version}.
References

Affected packages

openSUSE:Leap 16.0 / capnproto

Package

Name
capnproto
Purl
pkg:rpm/opensuse/capnproto&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.0-160000.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "capnproto":  "1.4.0-160000.1.1",
            "libcapnp-1_4_0":  "1.4.0-160000.1.1",
            "libcapnp-devel":  "1.4.0-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21062-1.json"