Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE Capnproto Moderate HTTP Smuggling Vulnerability 2026-21062-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
This update for openSUSE addresses vulnerabilities in capnproto that can lead to HTTP smuggling and includes important bug fixes.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for capnproto fixes the following issues:

Update to version 1.4.0.

Security issues fixed:

- CVE-2026-32239: negative `Content-Length` conversion treated as impossibly large length by KJ-HTTP can lead to HTTP

smuggling (bsc#1259638).

- CVE-2026-32240: integer overflow when KJ-HTTP `Transfer-Encoding` chunk size is parsed to a value of 2^64 or larger

can lead to HTTP smuggling (bsc#1259639).

Other updates and bugfixes:

- Have `stdcoro` use `::std` namespace.

- Disable stack check when HWASan is used.

- Fix benign buffer overrun in async `readMessage()`.

- Shared library naming changes from `libsomething-%{version}.so` to `libsomething.so.%{version}`.

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-1083=1

Patch

Package List

- openSUSE Leap 16.0:

capnproto-1.4.0-160000.1.1

libcapnp-1_4_0-1.4.0-160000.1.1

libcapnp-devel-1.4.0-160000.1.1

References

* bsc#1259638

* bsc#1259639

References:

* https://www.suse.com/security/cve/CVE-2026-32239.html

* https://www.suse.com/security/cve/CVE-2026-32240.html

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21062-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here