Bug 2445149
| Summary: | CVE-2026-3632 CVE-2026-3633 CVE-2026-3634 libsoup3: various flaws [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Michal Findra <mfindra> |
| Component: | libsoup3 | Assignee: | Gwyn Ciesla <gwync> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 45 | CC: | avovk, gnome-sig, gwync, mcrha |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["8d6027f7-19a9-4397-ad3d-094f4af57e98", "ff9221ad-4692-41c2-acd8-82e68348a8a0", "3cfb5eab-93c6-4178-8088-b6412b4e98f5"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2445127, 2445128, 2445129 | ||
|
Description
Michal Findra
2026-03-06 08:30:37 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45. Update on the current status of this tracker (which tracks 3 CVEs at once, for some reason...) Seems (no for-certain confirmation yet on the upstream tracker) like CVE-2026-3632 might have been fixed already in https://gitlab.gnome.org/GNOME/libsoup/-/commit/167ef0c6817658c1a089c75c462482209e207db4, which is the fix for CVE-2026-1467, which was addressed in https://bugzilla.redhat.com/show_bug.cgi?id=2433180 and https://bugzilla.redhat.com/show_bug.cgi?id=2433177 CVE-2026-3633 has a proposed fix: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/554 CVE-2026-3634 was fixed in https://gitlab.gnome.org/GNOME/libsoup/-/work_items/486, which is the fix for CVE-2026-1536, which was fixed in https://bugzilla.redhat.com/show_bug.cgi?id=2433838. The upstream tracker was closed to confirm this |