Release Info

Advisory: CLSA-2026:1771519663

OS: CentOS 7 ELS

Public date: 2026-02-19 16:47:45.787113

Project: libsoup

Version: 2.62.2-2.0.5.el7.tuxcare.els4

ETA for 100% rollout: 2026-03-06

Errata link: https://errata.tuxcare.com/els_os/centos7els/CLSA-2026-1771519663.html

Changelog

- CVE-2026-1761: fix stack-based buffer overflow in multipart HTTP response parsing caused by incorrect length calculation in soup_filter_input_stream_read_until() - CVE-2026-0719: fix stack-based buffer overflow in NTLM authentication caused by integer overflow in md4sum() with excessively long passwords

Update

Update command: yum update libsoup* Immediate update (via bypass): yum update libsoup* --enablerepo=centos7els-rollout-3-bypass

Packages list

libsoup-2.62.2-2.0.5.el7.tuxcare.els4.i686.rpm libsoup-2.62.2-2.0.5.el7.tuxcare.els4.x86_64.rpm libsoup-devel-2.62.2-2.0.5.el7.tuxcare.els4.i686.rpm libsoup-devel-2.62.2-2.0.5.el7.tuxcare.els4.x86_64.rpm

CVEs

CVE-2026-1761
CVE-2026-0719