[AutoPR- Security] Patch libsoup for CVE-2026-77014 [MEDIUM] - #18600
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
|
Patch Analysis — CVE-2026-77014 (libsoup 3.4.4) Backported: Yes e82c13ba: — Fix — compare in full 64-bit, 6ece9e52 — validate Fix — adds a 546a59d - RFC 416 — Files changed
Backport notes:
Verification POC Summary — CVE-2026-77014 (range-sort truncation) Idea: Request two byte ranges whose 64-bit start-difference overflows the old 32-bit comparator, on a >2 GB resource. Buggy lib mis-sorts and drops a range. Vulnerability reproduced on unpatched lib Fix verified on patched lib |
|
Buddy Build has been re-triggered and it has passed. Peer-review analysis - LGTM. |





Auto Patch libsoup for CVE-2026-77014.
Autosec pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1189685&view=results
CVE-2026-77014 : Single Patch Backporter Pipeline Run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1189691&view=results
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-staticsubpackages, etc.) have had theirReleasetag incremented../cgmanifest.json,./toolkit/scripts/toolchain/cgmanifest.json,.github/workflows/cgmanifest.json)./LICENSES-AND-NOTICES/SPECS/data/licenses.json,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON)*.signatures.jsonfilessudo make go-tidy-allandsudo make go-test-coveragepassSummary
What does the PR accomplish, why was it needed?
Change Log
Does this affect the toolchain?
YES/NO
Associated issues
Links to CVEs
Test Methodology