Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0868 - Security Advisory
Issued:
2026-01-20
Updated:
2026-01-20

RHSA-2026:0868 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libsoup security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libsoup is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

  • libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) (CVE-2025-14523)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2421349 - CVE-2025-14523 libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins)

CVEs

  • CVE-2025-14523

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
libsoup-2.72.0-8.el9_2.8.src.rpm SHA-256: 0d17d33cb740f3a4538586dde36a9a89bf98d26a4df59b8413a4d3761ea43ba8
x86_64
libsoup-2.72.0-8.el9_2.8.i686.rpm SHA-256: 55c9a5579932026ef22f5e478810ab145ccac301fd8507df2a2cb0e83b2ff4b3
libsoup-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: 55f72d03e6333c1eda7ceb5ad664326a01b3c306c5c0dc397b22e0973ce4b177
libsoup-debuginfo-2.72.0-8.el9_2.8.i686.rpm SHA-256: c8655920d5508fdbeabbcb3ad1cbe84e8725d566f3d5350a78f969990aecee6c
libsoup-debuginfo-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: 46837e62c2c6155b1ad5d15f3ec499bd471331c07f6386fc13d68c7da79f0cfc
libsoup-debugsource-2.72.0-8.el9_2.8.i686.rpm SHA-256: e7bde372637075953376bf43ac2dd970d540f8ac104cef6e94050a2950f36c4a
libsoup-debugsource-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: 69ea79a5f94447f70346c09aafcb7e28dd6a9a2a60831d593ef1055d9d32e71a
libsoup-devel-2.72.0-8.el9_2.8.i686.rpm SHA-256: 088d7830934837b3d8aab606975740c3adb523183c207959ab971ba9822ecf26
libsoup-devel-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: f7afaa8524d2207ac6c144208600c1542e625ef45020e3b49c53fe81778fe64c

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
libsoup-2.72.0-8.el9_2.8.src.rpm SHA-256: 0d17d33cb740f3a4538586dde36a9a89bf98d26a4df59b8413a4d3761ea43ba8
ppc64le
libsoup-2.72.0-8.el9_2.8.ppc64le.rpm SHA-256: 2d1315061890856a28c17c8b59507113389b9a722555bf18278025d48022df72
libsoup-debuginfo-2.72.0-8.el9_2.8.ppc64le.rpm SHA-256: ce97ff569b994c3ed3099df3f7441651ab1f5e9635dc09862f3c85b5853adf03
libsoup-debugsource-2.72.0-8.el9_2.8.ppc64le.rpm SHA-256: 9b342a47b9594c12b7040eb8a76c0d813fe41363fdd93e8619ae156f7be3a9f2
libsoup-devel-2.72.0-8.el9_2.8.ppc64le.rpm SHA-256: f389c06b3ab4122ba022251a21d3796b9f5dd705d8e07ea4f97d992bf947abdb

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
libsoup-2.72.0-8.el9_2.8.src.rpm SHA-256: 0d17d33cb740f3a4538586dde36a9a89bf98d26a4df59b8413a4d3761ea43ba8
x86_64
libsoup-2.72.0-8.el9_2.8.i686.rpm SHA-256: 55c9a5579932026ef22f5e478810ab145ccac301fd8507df2a2cb0e83b2ff4b3
libsoup-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: 55f72d03e6333c1eda7ceb5ad664326a01b3c306c5c0dc397b22e0973ce4b177
libsoup-debuginfo-2.72.0-8.el9_2.8.i686.rpm SHA-256: c8655920d5508fdbeabbcb3ad1cbe84e8725d566f3d5350a78f969990aecee6c
libsoup-debuginfo-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: 46837e62c2c6155b1ad5d15f3ec499bd471331c07f6386fc13d68c7da79f0cfc
libsoup-debugsource-2.72.0-8.el9_2.8.i686.rpm SHA-256: e7bde372637075953376bf43ac2dd970d540f8ac104cef6e94050a2950f36c4a
libsoup-debugsource-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: 69ea79a5f94447f70346c09aafcb7e28dd6a9a2a60831d593ef1055d9d32e71a
libsoup-devel-2.72.0-8.el9_2.8.i686.rpm SHA-256: 088d7830934837b3d8aab606975740c3adb523183c207959ab971ba9822ecf26
libsoup-devel-2.72.0-8.el9_2.8.x86_64.rpm SHA-256: f7afaa8524d2207ac6c144208600c1542e625ef45020e3b49c53fe81778fe64c

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
libsoup-2.72.0-8.el9_2.8.src.rpm SHA-256: 0d17d33cb740f3a4538586dde36a9a89bf98d26a4df59b8413a4d3761ea43ba8
aarch64
libsoup-2.72.0-8.el9_2.8.aarch64.rpm SHA-256: 5cf99d2e6d40463252b070cc75e21660649f72ad276ae41308b3560edd7d6669
libsoup-debuginfo-2.72.0-8.el9_2.8.aarch64.rpm SHA-256: 575fad77e4c307c9d0a3f357599e2604645a2621836968a9de417507edd3ea05
libsoup-debugsource-2.72.0-8.el9_2.8.aarch64.rpm SHA-256: eab0ada6c1ee8f2b224fb023c1d846203abd2b55efddd9765bafe33b8e5fe626
libsoup-devel-2.72.0-8.el9_2.8.aarch64.rpm SHA-256: 5159163df7e927e54aa88db16b5358c687c5a5ef7e5219dd152778e5b004a39e

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
libsoup-2.72.0-8.el9_2.8.src.rpm SHA-256: 0d17d33cb740f3a4538586dde36a9a89bf98d26a4df59b8413a4d3761ea43ba8
s390x
libsoup-2.72.0-8.el9_2.8.s390x.rpm SHA-256: 1a9fd06ca99e720f33bd734b22c0d978c2108e0c89d3cba4463862092c6a76d9
libsoup-debuginfo-2.72.0-8.el9_2.8.s390x.rpm SHA-256: f90eaf1e6d318988aa3b226e47a656e9050f8ed918161422747d990733450dc0
libsoup-debugsource-2.72.0-8.el9_2.8.s390x.rpm SHA-256: 94649b53e067f6723bbee80554508226dbe9c6ce85985f356978af138f5df52a
libsoup-devel-2.72.0-8.el9_2.8.s390x.rpm SHA-256: ecb0dc08c850f43afe315c4eb1884a1587d173c04f5562e4a7ebf1cd6a38f8cd

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility