libsoup-2.72.0-16.el9_8.3

エラータID: AXSA:2026-1872:12

Release date: 
Friday, September 18, 2026 - 11:22
Subject: 
libsoup-2.72.0-16.el9_8.3
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

* SoupWebsocketExtensionDeflate: libsoup: libsoup: WebSocket permessage-deflate Unbounded Decompression Remote Denial of Service (CVE-2026-15709)
* libsoup: SoupWebsocketConnection: libsoup: WebSocket remote denial of service via oversized control frame protocol violation (CVE-2026-15711)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-15709
A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).
CVE-2026-15711
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libsoup-2.72.0-16.el9_8.3.src.rpm
    MD5: 49077d4894a1c83060b9fe3adc67cda9
    SHA-256: 684b3b751b08f839b9b74934723914e907155714edbb3a5d50c22b50610e5854
    Size: 1.47 MB

Asianux Server 9 for x86_64
  1. libsoup-2.72.0-16.el9_8.3.i686.rpm
    MD5: 913c576ed8154d6bf9b07e123d3bb27c
    SHA-256: b164ea2f10d8d756f44f26586313d3f7298caeb3964b2b95abdaac055634ec01
    Size: 427.33 kB
  2. libsoup-2.72.0-16.el9_8.3.x86_64.rpm
    MD5: a98256b973abf413789fccc5ce996af8
    SHA-256: 6241ddd0dff1a1e974444aedb762fca3876492de908fb0108581eafc68f45f0b
    Size: 407.04 kB
  3. libsoup-devel-2.72.0-16.el9_8.3.i686.rpm
    MD5: 368d33852fc0584b47b63c92e8eab90a
    SHA-256: d324235b5641e9245d93c58d1514ba832503af82f1b9e92a5c51dc7e26fbfaea
    Size: 181.04 kB
  4. libsoup-devel-2.72.0-16.el9_8.3.x86_64.rpm
    MD5: 3831b3faf3bfa22ef48413e493edc768
    SHA-256: 908c90d5d0da19dc302b57fd8840d93d141757d6ced57b9f6e6d6d0c4a1351d3
    Size: 181.07 kB