Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE Linux Micro 6.0 libsoup Important Denial of Service Fix 2026-20529-1

suse
Calendar Grey March 3, 2026
Dist Suse Esm H88
Fixes five security issues for libsoup, including denial of service concerns to improve system protection.
An update that solves five vulnerabilities can now be installed.

Summary

## This update for libsoup fixes the following issues: * CVE-2025-12105: Fixed heap use-after-free in message queue handling during HTTP/2 read completion. (bsc#1252555) * CVE-2025-32049: Fixed a Denial of Service attack to websocket server. (bsc#1240751) * CVE-2026-2443: Fixed an out-of-bounds read when processing specially crafted HTTP Range headers can lead to heap information disclosure to remote attackers. (bsc#1258170) * CVE-2026-2369: Fixed a buffer overread due to integer underflow when handling zero-length resources. (bsc#1258120) * CVE-2026-2708: Fixed HTTP request smuggling via duplicate Content-Length headers. (bsc#1258508) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

* bsc#1240751

* bsc#1252555

* bsc#1258120

* bsc#1258170

* bsc#1258508

Cross-

* CVE-2025-12105

* CVE-2025-32049

* CVE-2026-2369

* CVE-2026-2443

* CVE-2026-2708

CVSS scores:

* CVE-2025-12105 ( SUSE ): 8.8

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

* CVE-2025-12105 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

* CVE-2025-12105 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-32049 ( SUSE ): 7.1

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-32049 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-32049 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-2369 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:20529-1
Release Date: 2026-03-02T13:19:17Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here