[El-errata] ELSA-2026-68235 Important: Oracle Linux 10 libsoup3 security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Fri Sep 18 08:51:40 UTC 2026
Oracle Linux Security Advisory ELSA-2026-68235
http://linux.oracle.com/errata/ELSA-2026-68235.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
libsoup3-3.6.5-3.el10_2.14.x86_64.rpm
libsoup3-devel-3.6.5-3.el10_2.14.x86_64.rpm
libsoup3-doc-3.6.5-3.el10_2.14.noarch.rpm
aarch64:
libsoup3-3.6.5-3.el10_2.14.aarch64.rpm
libsoup3-devel-3.6.5-3.el10_2.14.aarch64.rpm
libsoup3-doc-3.6.5-3.el10_2.14.noarch.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libsoup3-3.6.5-3.el10_2.14.src.rpm
Related CVEs:
CVE-2026-15709
CVE-2026-15711
CVE-2026-85197
Description of changes:
[3.6.5-14]
- Fix CVE-2026-85197: http2 crash after connection destroyed
[3.6.5-13]
- Fix CVE-2026-15711: Reject oversized WebSocket control frames
[3.6.5-12]
- Fix CVE-2026-15709: bound decompressed WebSocket message size
[3.6.5-11]
- Add patches for CVE-2026-4271 and CVE-2026-5119
[3.6.5-10]
- Add patch for CVE-2026-1761
[3.6.5-9]
- Fix CVE-2026-0719
[3.6.5-8]
- Fix CVE-2025-14523
[3.6.5-7]
- Add patch for CVE-2025-12105
[3.6.5-6]
- Fix integer overflow in date/time parsing
[3.6.5-5]
- Bump revision number
More information about the El-errata
mailing list