USN-8890-1: eight libsoup flaws, from DoS to possible code execution
Ubuntu publishes USN-8890-1: eight CVEs in libsoup2.4 and libsoup3, ranging from denial of service to possible code execution via HTTP/2.
UptimeMag editorial team · 7 October 2026 · 2 min read

On 6 October 2026, Ubuntu published the USN-8890-1 advisory, fixing eight vulnerabilities in libsoup2.4 and libsoup3, the HTTP client/server libraries used by GNOME and everything built on top of it. For anyone managing Ubuntu desktops or servers with graphical components or services relying on libsoup, this is an update to schedule straight away, not one to put off until the next maintenance window.\n\n## The most significant flaws\n\nThe most serious is CVE-2026-85197: improper handling of certain HTTP/2 connections that a remote attacker could exploit to obtain sensitive information or execute arbitrary code. It affects Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS.\n\nThe other seven flaws range from denial of service (CVE-2026-4271 on HTTP/2 requests, CVE-2026-85534 on HTTP/2 transfers, CVE-2026-77014 and CVE-2026-77680 on HTTP Range headers) to information disclosure (CVE-2026-5119 on HTTPS proxy connections, CVE-2026-66339 on proxy authentication credentials) through to bypassing security checks (CVE-2026-6324 on malformed chunked HTTP requests).\n\n## Fixed versions\n\n| Release | Package | Fixed version |\n|---|---|---|\n| 26.04 LTS (resolute) | libsoup-3.0-0 | 3.6.6-1ubuntu0.1 |\n| 26.04 LTS (resolute) | libsoup-2.4-1 | 2.74.3-10.1ubuntu5+esm3 (Ubuntu Pro ESM Apps) |\n| 24.04 LTS (noble) | libsoup-3.0-0 | 3.4.4-5ubuntu0.9 |\n| 24.04 LTS (noble) | libsoup-2.4-1 | 2.74.3-6ubuntu1.9 |\n| 22.04 LTS (jammy) | libsoup-3.0-0 | 3.0.7-0ubuntu1+esm9 (Ubuntu Pro ESM Apps) |\n| 22.04 LTS (jammy) | libsoup2.4-1 | 2.74.2-3ubuntu0.9 |\n| 20.04 LTS (focal) | libsoup2.4-1 | 2.70.0-1ubuntu0.5+esm4 (Ubuntu Pro) |\n| 18.04 LTS (bionic) | libsoup2.4-1 | 2.62.1-1ubuntu0.4+esm9 (Ubuntu Pro) |\n| 16.04 LTS (xenial) | libsoup2.4-1 | 2.52.2-1ubuntu0.3+esm8 (Ubuntu Pro Legacy Support) |\n\nOn 26.04 LTS and 22.04 LTS, the libsoup2.4 and libsoup-3.0 packages for jammy require an Ubuntu Pro subscription via ESM Apps to receive the patch; on focal, bionic and xenial, Ubuntu Pro is required for all fixed versions of the package.\n\n## How to update\n\nOn systems with standard repositories, a regular system update is enough:\n\n\nsudo apt update && sudo apt upgrade\n\n\nWhere ESM Apps or Ubuntu Pro is required, check the subscription status with pro status before proceeding.\n\nSource: official Ubuntu Security Notices advisory, USN-8890-1, published on 6 October 2026.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.