[El-errata] ELSA-2026-68235 Important: Oracle Linux 10 libsoup3 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Sep 18 08:51:40 UTC 2026


Oracle Linux Security Advisory ELSA-2026-68235

http://linux.oracle.com/errata/ELSA-2026-68235.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
libsoup3-3.6.5-3.el10_2.14.x86_64.rpm
libsoup3-devel-3.6.5-3.el10_2.14.x86_64.rpm
libsoup3-doc-3.6.5-3.el10_2.14.noarch.rpm

aarch64:
libsoup3-3.6.5-3.el10_2.14.aarch64.rpm
libsoup3-devel-3.6.5-3.el10_2.14.aarch64.rpm
libsoup3-doc-3.6.5-3.el10_2.14.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/libsoup3-3.6.5-3.el10_2.14.src.rpm

Related CVEs:

CVE-2026-15709
CVE-2026-15711
CVE-2026-85197




Description of changes:

[3.6.5-14]
- Fix CVE-2026-85197: http2 crash after connection destroyed

[3.6.5-13]
- Fix CVE-2026-15711: Reject oversized WebSocket control frames

[3.6.5-12]
- Fix CVE-2026-15709: bound decompressed WebSocket message size

[3.6.5-11]
- Add patches for CVE-2026-4271 and CVE-2026-5119

[3.6.5-10]
- Add patch for CVE-2026-1761

[3.6.5-9]
- Fix CVE-2026-0719

[3.6.5-8]
- Fix CVE-2025-14523

[3.6.5-7]
- Add patch for CVE-2025-12105

[3.6.5-6]
- Fix integer overflow in date/time parsing

[3.6.5-5]
- Bump revision number




More information about the El-errata mailing list