#1146877 libsoup3: CVE-2026-85197

Package:
src:libsoup3
Source:
src:libsoup3
Submitter:
Salvatore Bonaccorso
Date:
2026-10-01 11:23:14 UTC
Severity:
normal
Tags:
#1146877#5
Date:
2026-09-06 16:01:25 UTC
From:
To:
Hi,

The following vulnerability was published for libsoup3.

CVE-2026-85197[0]:
| A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-
| the-Middle (MITM) attacker can exploit a heap use-after-free
| vulnerability in the HTTP/2 client implementation. This occurs when
| a GNOME application uploads a file using HTTP/2, and the server
| sends a GOAWAY frame while the file body is being read
| asynchronously. This can lead to memory corruption, potentially
| resulting in information disclosure or arbitrary code execution.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-85197
https://www.cve.org/CVERecord?id=CVE-2026-85197
[1] https://gitlab.gnome.org/GNOME/libsoup/-/work_items/552

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1146877#12
Date:
2026-10-01 05:49:26 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libsoup3, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146877@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated libsoup3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 01 Oct 2026 07:27:21 +0200
Source: libsoup3
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.8.0-1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1102067 1125083 1128582 1129316 1130498 1130500 1130501 1131447 1132331 1138213 1140924 1142836 1142837 1142838 1142839 1142840 1142841 1142842 1142843 1142844 1142845 1142846 1144976 1145785 1146877 1146878
Launchpad-Bugs-Fixed: 2169104
Changes:
 libsoup3 (3.8.0-1) unstable; urgency=high
 .
   * New upstream release (LP: #2169104)
     - SECURITY UPDATE:
       - CVE-2025-32049 (Closes: #1102067)
       - CVE-2026-0719 (Closes: #1125083)
       - CVE-2026-1536 (Closes: #1130501)
       - CVE-2026-2436 (Closes: #1130498)
       - CVE-2026-2708 (Closes: #1128582)
       - CVE-2026-3099 (Closes: #1129316)
       - CVE-2026-3633 (Closes: #1130500)
       - CVE-2026-3634 (Closes: #1130501)
       - CVE-2026-4271 (Closes: #1131447)
       - CVE-2026-5119 (Closes: #1132331)
       - CVE-2026-6324 (Closes: #1138213)
       - CVE-2026-12478 (Closes: #1142836)
       - CVE-2026-12547 (Closes: #1142837)
       - CVE-2026-12548 (Closes: #1142838)
       - CVE-2026-12549 (Closes: #1140924)
       - CVE-2026-15709 (Closes: #1142839)
       - CVE-2026-15711 (Closes: #1142840)
       - CVE-2026-15712 (Closes: #1142841)
       - CVE-2026-15713 (Closes: #1142842)
       - CVE-2026-15714 (Closes: #1142843)
       - CVE-2026-66337 (Closes: #1142844)
       - CVE-2026-66338 (Closes: #1142845)
       - CVE-2026-66339 (Closes: #1142846)
       - CVE-2026-77014 (Closes: #1144976)
       - CVE-2026-77680 (Closes: #1145785)
       - CVE-2026-85197 (Closes: #1146877)
       - CVE-2026-85534 (Closes: #1146878)
       - CVE-2026-102555
       - CVE-2026-102556
       - CVE-2026-102557
       - CVE-2026-102558
       - CVE-2026-102559
       - CVE-2026-102560
       - CVE-2026-103399
   * libsoup-3.0-0.symbols: Add new symbols
   * Add Build-Depends: libzstd-dev
   * Add patch to revert build test change that doesn't work for 32-bit architectures
   * Remove one security patch applied in new release
   * Build with debhelper compat 14
   * Run wrap-and-sort -ast
   * Update debian/upstream/metadata
   * Update Standards Version to 4.7.4
Checksums-Sha1:
 1c299050b87395934378356c25114e09ebb978d1 2982 libsoup3_3.8.0-1.dsc
 d5b88a826b98e0bfe3f74435b0e9d6500a3951b7 1609676 libsoup3_3.8.0.orig.tar.xz
 e453b767b0a8f5ef0ba94747e357a5ab7ff3b099 31196 libsoup3_3.8.0-1.debian.tar.xz
 2ddb5b043eb285c83c4680cff9c98f7d0ae25a74 13336 libsoup3_3.8.0-1_source.buildinfo
Checksums-Sha256:
 ec527da7e94913df677ba66c1692e733d2fad0e84214f93608a379470b6ddf7f 2982 libsoup3_3.8.0-1.dsc
 bbf08fa3e03a88c31a3d27a0d87cb422e9490f2d08e149211103df6d638a2238 1609676 libsoup3_3.8.0.orig.tar.xz
 a5a14b5c78ddbf77c36e6b34c300f3e671b3241d32ae253f1132927a8b59d043 31196 libsoup3_3.8.0-1.debian.tar.xz
 42e4d73348017b12426e7f56a620909685e5e7a095da07057bc2d0665b43866c 13336 libsoup3_3.8.0-1_source.buildinfo
Files:
 5577463c458f849da8c2ecca700512fb 2982 devel optional libsoup3_3.8.0-1.dsc
 3e7e404362998102b602698c799a0759 1609676 devel optional libsoup3_3.8.0.orig.tar.xz
 c2c1604f59c544c45ee2cbb3f3506caa 31196 devel optional libsoup3_3.8.0-1.debian.tar.xz
 43a27af70845ed920469c50864ff3caf 13336 devel optional libsoup3_3.8.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmq97+MACgkQ5mx3Wuv+
bH3qdw//Y6fS/wc52jK+l/eLKtJMJMT5sjVKZMauLOLRc4YvY2VSMJpbhoNkcAU+
3vIF07X8c+1Fa2LqB/HKeaqvAwHFJufx3fgrk89Wt/5WvJrlobReYUJ3KZGfdSil
xpXs8SRe8Fhol+SS7aON14V7pk9sgd/e46mUKucurGdLPxoKTksVwoO31+nB/toQ
U0NmCPomdcmfeB2QGwvOaSbvjUhbKee3Mvv3gLsaPCuzy5D1VOFB9WXh4KzlfIyf
3Fd05oCvYgAU+e8AgPunnochTfTxaOtdbQ8gXjwp1LvZES1zitKuSY7dCoVkGUtQ
p8Se/IBozAGsEQvYypERCpOWh57rtwf4Yrk5AbsmsZo9Sjl42D0OJ0a+ln83nWhG
4NgQ5AnbBop7I7TrlxFZBbDPrWP4TafZNOemqv5YUlN6vud2hpLuHv1V2B0rEU1H
FZGXtOu2DkR2sK2sXlb00WB4NqwChIyrRjL1j8eGvDDFYLtOwCxRM/h/jGvVpVxl
LAiZkj1z7TNwu/BTevBnAC5r9u8xO8R7OmFAcPw28L+CzP50tDEYss19mLnRKUs6
1uV9xMEqxrg1ykHrUHrD56PJx+/OqFb9jrAg6Ab3kzY1z0QybZ20Wq0OZULmsReO
XFidASnb11zRLIpF8TBaqM9iDXLTgSBT4aykUAlsx/a8U6vZqC4=
=SD8B
-----END PGP SIGNATURE-----

#1146877#17
Date:
2026-10-01 11:20:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libsoup3, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146877@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated libsoup3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 01 Oct 2026 12:55:13 +0200
Source: libsoup3
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.8.0-2
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1102067 1125083 1128582 1129316 1130498 1130500 1130501 1131447 1132331 1138213 1140924 1142836 1142837 1142838 1142839 1142840 1142841 1142842 1142843 1142844 1142845 1142846 1144976 1145785 1146877 1146878
Launchpad-Bugs-Fixed: 2169104
Changes:
 libsoup3 (3.8.0-2) unstable; urgency=high
 .
   * Add patch to revert a change in tests/cookies-test.c that broke
     the test for armhf (but not i386)
 .
 libsoup3 (3.8.0-1) unstable; urgency=high
 .
   * New upstream release (LP: #2169104)
     - SECURITY UPDATE:
       - CVE-2025-32049 (Closes: #1102067)
       - CVE-2026-0719 (Closes: #1125083)
       - CVE-2026-1536 (Closes: #1130501)
       - CVE-2026-2436 (Closes: #1130498)
       - CVE-2026-2708 (Closes: #1128582)
       - CVE-2026-3099 (Closes: #1129316)
       - CVE-2026-3633 (Closes: #1130500)
       - CVE-2026-3634 (Closes: #1130501)
       - CVE-2026-4271 (Closes: #1131447)
       - CVE-2026-5119 (Closes: #1132331)
       - CVE-2026-6324 (Closes: #1138213)
       - CVE-2026-12478 (Closes: #1142836)
       - CVE-2026-12547 (Closes: #1142837)
       - CVE-2026-12548 (Closes: #1142838)
       - CVE-2026-12549 (Closes: #1140924)
       - CVE-2026-15709 (Closes: #1142839)
       - CVE-2026-15711 (Closes: #1142840)
       - CVE-2026-15712 (Closes: #1142841)
       - CVE-2026-15713 (Closes: #1142842)
       - CVE-2026-15714 (Closes: #1142843)
       - CVE-2026-66337 (Closes: #1142844)
       - CVE-2026-66338 (Closes: #1142845)
       - CVE-2026-66339 (Closes: #1142846)
       - CVE-2026-77014 (Closes: #1144976)
       - CVE-2026-77680 (Closes: #1145785)
       - CVE-2026-85197 (Closes: #1146877)
       - CVE-2026-85534 (Closes: #1146878)
       - CVE-2026-102555
       - CVE-2026-102556
       - CVE-2026-102557
       - CVE-2026-102558
       - CVE-2026-102559
       - CVE-2026-102560
       - CVE-2026-103399
   * libsoup-3.0-0.symbols: Add new symbols
   * Add Build-Depends: libzstd-dev
   * Add patch to revert build test change that doesn't work for 32-bit architectures
   * Remove one security patch applied in new release
   * Build with debhelper compat 14
   * Run wrap-and-sort -ast
   * Update debian/upstream/metadata
   * Update Standards Version to 4.7.4
Checksums-Sha1:
 4dac1ced3a4539fb211a746973adc065182b6043 2982 libsoup3_3.8.0-2.dsc
 d5b88a826b98e0bfe3f74435b0e9d6500a3951b7 1609676 libsoup3_3.8.0.orig.tar.xz
 ffe862a69beae0fc805373f57c49426d97663b6c 32580 libsoup3_3.8.0-2.debian.tar.xz
 3e1b48ef964dc47c9b1acfaa4c025d0a84c09fda 13336 libsoup3_3.8.0-2_source.buildinfo
Checksums-Sha256:
 1295f39ce9d989f8ac8440d9bc291694fa8c45a574784f6f1d1f2bae955268c5 2982 libsoup3_3.8.0-2.dsc
 bbf08fa3e03a88c31a3d27a0d87cb422e9490f2d08e149211103df6d638a2238 1609676 libsoup3_3.8.0.orig.tar.xz
 1f8137a16beac36768ba661a0ce830914aab80136244651d33fb959ff0f6f244 32580 libsoup3_3.8.0-2.debian.tar.xz
 81d6112928bdfb77861f217531438a509de301b700ed3c890375662805287324 13336 libsoup3_3.8.0-2_source.buildinfo
Files:
 e18914f84604b92217cc0e09df292021 2982 devel optional libsoup3_3.8.0-2.dsc
 3e7e404362998102b602698c799a0759 1609676 devel optional libsoup3_3.8.0.orig.tar.xz
 5f51c45c469d9c7bfca853edc97443cb 32580 devel optional libsoup3_3.8.0-2.debian.tar.xz
 1af45e206139eecbd78768d7f03c0462 13336 devel optional libsoup3_3.8.0-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmq+PCkACgkQ5mx3Wuv+
bH0iJw/9EPJaFd/HautEZz4EDFnJwnrB8l3mz85hSN1IaAgo9CdcVg+fjU4kpXd6
u8GnILbHBDKaO9nXSrM6ejnFkCmgHmZ/HqmP0sY3CpZLEsQU1GxAiDjFeA9ffefh
C5AFtaN0Xj2iG2rmnTAy6ZbWq7+RPdHES4NdPuEUItmAS2y67TOAa9TJKKr8kavM
6wHJ+9CFbFo3zv0/xxjuXSW+JWxm204/+W674HUCISbMQ6a3LubnTfZ0dVJegXWy
KoOjM50r3gafLakjZ3G4Mp++gSUqKH7o6EmMDAvEhkFm9Z82KB/YVKtEedAP4d3Z
jYVeK6TZBWhFXwoy97ngLI3kML4BiQvnzTyRG4CaM7Lzj5Q4dF4ZTqW7PQETq2Qb
Z1Jppfm53GZ3REn2JgfBdCG9csh8IXYrqjyt5W/78hXSzKGbZhMvMBlIL5FfHh4T
lM02KXofLnQ0mU25eIrjXRUkW1OUm26O8YUMW/oRBY7z/dvziNnPy2xuX36zFuAe
i6gqkSfCscOCnUa8WyW5ZSyDI8tou7tUrU0FrTQs91i8i/Btw5XiqQhA4IozOQ6X
FBqAVbnjh7FgYnjgMx5zpMji+uMh2YJjN+rIHoQtXDYWOT/XWw5VF2UmPMFr5+et
mkWwDmTVN6Xk5HtMl/AE7gvSjuhJ7fO90V3buFK8re8E4nI5e6Y=
=/+0N
-----END PGP SIGNATURE-----