Home / mailings [USN-8890-1] libsoup vulnerabilities
Posted on 07 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8890-1
October 06, 2026
libsoup2.4, libsoup3 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in libsoup.
Software Description:
- libsoup2.4: HTTP client/server library for GNOME
- libsoup3: HTTP client/server library for GNOME
Details:
It was discovered that libsoup incorrectly handled certain HTTP/2 requests.
A remote attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-4271)
It was discovered that libsoup incorrectly handled certain HTTPS proxy
connections. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-5119)
It was discovered that libsoup incorrectly parsed certain chunked HTTP
requests. A remote attacker could possibly use this issue to bypass
security controls. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-6324)
It was discovered that libsoup incorrectly handled proxy authentication
credentials. A remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2026-66339)
It was discovered that libsoup incorrectly handled certain HTTP Range
headers. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2026-77014, CVE-2026-77680)
It was discovered that libsoup incorrectly handled certain HTTP/2
connections. A remote attacker could possibly use this issue to obtain
sensitive information or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-85197)
It was discovered that libsoup incorrectly handled certain HTTP/2
transfers. A remote attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-85534)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
gir1.2-soup-2.4 2.74.3-10.1ubuntu5+esm3
Available with Ubuntu Pro
gir1.2-soup-3.0 3.6.6-1ubuntu0.1
libsoup-2.4-1 2.74.3-10.1ubuntu5+esm3
Available with Ubuntu Pro
libsoup-3.0-0 3.6.6-1ubuntu0.1
libsoup-3.0-common 3.6.6-1ubuntu0.1
libsoup-3.0-dev 3.6.6-1ubuntu0.1
libsoup-gnome-2.4-1 2.74.3-10.1ubuntu5+esm3
Available with Ubuntu Pro
libsoup-gnome2.4-dev 2.74.3-10.1ubuntu5+esm3
Available with Ubuntu Pro
libsoup2.4-common 2.74.3-10.1ubuntu5+esm3
Available with Ubuntu Pro
libsoup2.4-dev 2.74.3-10.1ubuntu5+esm3
Available with Ubuntu Pro
Ubuntu 24.04 LTS
gir1.2-soup-2.4 2.74.3-6ubuntu1.9
gir1.2-soup-3.0 3.4.4-5ubuntu0.9
libsoup-2.4-1 2.74.3-6ubuntu1.9
libsoup-3.0-0 3.4.4-5ubuntu0.9
libsoup-3.0-common 3.4.4-5ubuntu0.9
libsoup-3.0-dev 3.4.4-5ubuntu0.9
libsoup-gnome-2.4-1 2.74.3-6ubuntu1.9
libsoup-gnome2.4-dev 2.74.3-6ubuntu1.9
libsoup2.4-common 2.74.3-6ubuntu1.9
libsoup2.4-dev 2.74.3-6ubuntu1.9
Ubuntu 22.04 LTS
gir1.2-soup-2.4 2.74.2-3ubuntu0.9
gir1.2-soup-3.0 3.0.7-0ubuntu1+esm9
Available with Ubuntu Pro
libsoup-3.0-0 3.0.7-0ubuntu1+esm9
Available with Ubuntu Pro
libsoup-3.0-common 3.0.7-0ubuntu1+esm9
Available with Ubuntu Pro
libsoup-3.0-dev 3.0.7-0ubuntu1+esm9
Available with Ubuntu Pro
libsoup-gnome2.4-1 2.74.2-3ubuntu0.9
libsoup-gnome2.4-dev 2.74.2-3ubuntu0.9
libsoup2.4-1 2.74.2-3ubuntu0.9
libsoup2.4-common 2.74.2-3ubuntu0.9
libsoup2.4-dev 2.74.2-3ubuntu0.9
Ubuntu 20.04 LTS
gir1.2-soup-2.4 2.70.0-1ubuntu0.5+esm4
Available with Ubuntu Pro
libsoup-gnome2.4-1 2.70.0-1ubuntu0.5+esm4
Available with Ubuntu Pro
libsoup-gnome2.4-dev 2.70.0-1ubuntu0.5+esm4
Available with Ubuntu Pro
libsoup2.4-1 2.70.0-1ubuntu0.5+esm4
Available with Ubuntu Pro
libsoup2.4-dev 2.70.0-1ubuntu0.5+esm4
Available with Ubuntu Pro
Ubuntu 18.04 LTS
gir1.2-soup-2.4 2.62.1-1ubuntu0.4+esm9
Available with Ubuntu Pro
libsoup-gnome2.4-1 2.62.1-1ubuntu0.4+esm9
Available with Ubuntu Pro
libsoup-gnome2.4-dev 2.62.1-1ubuntu0.4+esm9
Available with Ubuntu Pro
libsoup2.4-1 2.62.1-1ubuntu0.4+esm9
Available with Ubuntu Pro
libsoup2.4-dev 2.62.1-1ubuntu0.4+esm9
Available with Ubuntu Pro
Ubuntu 16.04 LTS
gir1.2-soup-2.4 2.52.2-1ubuntu0.3+esm8
Available with Ubuntu Pro
libsoup-gnome2.4-1 2.52.2-1ubuntu0.3+esm8
Available with Ubuntu Pro
libsoup-gnome2.4-dev 2.52.2-1ubuntu0.3+esm8
Available with Ubuntu Pro
libsoup2.4-1 2.52.2-1ubuntu0.3+esm8
Available with Ubuntu Pro
libsoup2.4-dev 2.52.2-1ubuntu0.3+esm8
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8890-1
CVE-2026-4271, CVE-2026-5119, CVE-2026-6324, CVE-2026-66339,
CVE-2026-77014, CVE-2026-77680, CVE-2026-85197, CVE-2026-85534
Package Information:
https://launchpad.net/ubuntu/+source/libsoup2.4/2.74.3-6ubuntu1.9
https://launchpad.net/ubuntu/+source/libsoup3/3.4.4-5ubuntu0.9
--===============3346181809490486333==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
