ALAS2023-2026-2087


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2087
Advisory Released Date: 2026-08-31
Advisory Updated Date: 2026-08-31
Severity: Important

Issue Overview:

A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 SS5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets. (CVE-2026-15711)


Affected Packages:

libsoup3


Issue Correction:
Run dnf update libsoup3 --releasever 2023.12.20260831 or dnf update --advisory ALAS2023-2026-2087 --releasever 2023.12.20260831 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    libsoup3-debuginfo-3.6.6-59.amzn2023.aarch64
    libsoup3-debugsource-3.6.6-59.amzn2023.aarch64
    libsoup3-devel-3.6.6-59.amzn2023.aarch64
    libsoup3-3.6.6-59.amzn2023.aarch64

noarch:
    libsoup3-doc-3.6.6-59.amzn2023.noarch

src:
    libsoup3-3.6.6-59.amzn2023.src

x86_64:
    libsoup3-debuginfo-3.6.6-59.amzn2023.x86_64
    libsoup3-devel-3.6.6-59.amzn2023.x86_64
    libsoup3-debugsource-3.6.6-59.amzn2023.x86_64
    libsoup3-3.6.6-59.amzn2023.x86_64