CODERED VTA

Ubuntu Patches Eight libsoup Flaws Spanning HTTP2 Parsing Proxy Handling and Range Headers

High
Server racks in a data centre
Photo by Jeff Sheldon on Unsplash

Canonical has published security notice USN-8890-1, addressing eight separate vulnerabilities in libsoup, the HTTP client and server library present on Ubuntu systems. The issues span HTTP/2 request handling, HTTPS proxy connections, chunked transfer parsing, proxy authentication credentials and HTTP Range header processing. Four of the flaws, CVE-2026-5119, CVE-2026-6324, CVE-2026-85197 and CVE-2026-85534, are limited to Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS, while CVE-2026-4271 affects only Ubuntu 24.04 LTS and 26.04 LTS. Three further issues, CVE-2026-66339, CVE-2026-77014 and CVE-2026-77680, are not scoped to specific releases in the notice and apply across the affected Ubuntu versions it covers.

The advisory describes each weakness at a functional level and does not publish exploitation details or proof of concept code. In every case the attack vector is remote and reached through traffic that a vulnerable application processes. Malformed HTTP/2 requests and transfers can crash or stall the library, producing denial of service (CVE-2026-4271, CVE-2026-85534), while incorrectly handled HTTP/2 connections may expose sensitive information or allow arbitrary code execution (CVE-2026-85197). Mishandled HTTP Range headers give a further denial of service path (CVE-2026-77014, CVE-2026-77680), faults in HTTPS proxy connections and proxy authentication credential handling can leak sensitive data (CVE-2026-5119, CVE-2026-66339), and flawed parsing of chunked HTTP requests allows security controls that depend on consistent request framing to be bypassed (CVE-2026-6324).

The strategic concern is reach rather than any single flaw. libsoup is rarely installed deliberately; it arrives as a dependency of other packaged software, so a large estate can be exposed without any inventory entry naming it. Credential exposure through the proxy handling issues is the most sensitive outcome for enterprise environments where outbound traffic is funnelled through authenticated proxies, and the information disclosure and arbitrary code execution path in CVE-2026-85197 is the most severe of the eight. Fixed packages are published in USN-8890-1 for Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS, and the notice enumerates the fixed package version for each package on each of those releases. None of the eight CVEs appears in the CISA KEV catalogue, and FIRST EPSS places CVE-2026-4271 highest at a 1.3 percent probability of exploitation over the next 30 days, with the remaining seven between 0.2 and 0.5 percent.

Attack Surface

Endpoint OS, Server OS

Tactics

Execution, Credential Access, Defense Evasion, Impact, Collection

Techniques

  • T1203 – Exploitation for Client Execution
  • T1499 – Endpoint Denial of Service
  • T1557 – Adversary-in-the-Middle
  • T1212 – Exploitation for Credential Access

SuperPRO's Threat Countermeasures Procedures

  1. Apply the libsoup package updates published in Canonical security notice USN-8890-1 on Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS with sudo apt update followed by sudo apt install –only-upgrade on the libsoup packages, upgrading each to the release-specific fixed version enumerated in the notice, which closes CVE-2026-4271, CVE-2026-5119, CVE-2026-6324, CVE-2026-66339, CVE-2026-77014, CVE-2026-77680, CVE-2026-85197 and CVE-2026-85534.
  2. Scope exposure by matching the libsoup package names and release-specific fixed versions listed in USN-8890-1 against the installed package inventory of every Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS host, since libsoup is normally present as a dependency of other software rather than as a deliberate installation.
  3. Complete the update with the system restart that USN-8890-1 calls for, because libsoup is a shared library and processes started before the upgrade continue to run the unfixed code held in memory until the host is restarted.
  4. Prioritise Ubuntu 24.04 LTS and 26.04 LTS hosts for the HTTP/2 denial of service in CVE-2026-4271 and any release running HTTP/2 enabled clients for CVE-2026-85197, which the notice records as allowing information disclosure or arbitrary code execution.
  5. Treat proxy authentication credentials used by libsoup clients on unpatched Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS hosts as potentially exposed under CVE-2026-5119 and CVE-2026-66339, and rotate those proxy account passwords once the USN-8890-1 packages are in place.
  6. Monitor hosts that have not yet taken USN-8890-1 for repeated crashes or hangs of libsoup-linked applications as the observable signature of the denial of service issues CVE-2026-4271, CVE-2026-85534, CVE-2026-77014 and CVE-2026-77680, correlating them with HTTP/2 traffic and HTTP Range header requests handled by those applications.
  7. Verify remediation per release rather than per estate, confirming the installed libsoup version on each Ubuntu 22.04 LTS, 24.04 LTS and 26.04 LTS host matches the fixed version recorded for that release in USN-8890-1, noting that CVE-2026-4271 is scoped only to 24.04 LTS and 26.04 LTS.

Source

Code Red Cyber / VTA – coderedcyber.ai