From 6e84cb11dd3fca86d0e53192b083f59aef555974 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Thu, 1 Oct 2026 10:41:45 +0000 Subject: [PATCH] libsoup_3: 3.6.6 -> 3.8.0 Diff: https://gitlab.gnome.org/GNOME/libsoup/-/compare/3.6.6...3.8.0 Changelog: https://gitlab.gnome.org/GNOME/libsoup/-/blob/3.8.0/NEWS This fixes the following security issues: CVE-2026-3633 CVE-2026-15709 (https://github.com/NixOS/nixpkgs/issues/544160) CVE-2026-66338 (https://github.com/NixOS/nixpkgs/issues/545683) CVE-2026-66337 (https://github.com/NixOS/nixpkgs/issues/545680) CVE-2026-66339 (https://github.com/NixOS/nixpkgs/issues/545678) CVE-2026-85197 (https://github.com/NixOS/nixpkgs/issues/560171) CVE-2026-102555 (https://github.com/NixOS/nixpkgs/issues/568624) CVE-2026-102556 CVE-2026-102557 (https://github.com/NixOS/nixpkgs/issues/568640) CVE-2026-102558 (https://github.com/NixOS/nixpkgs/issues/568638) CVE-2026-102559 (https://github.com/NixOS/nixpkgs/issues/568632) CVE-2026-102560 (https://github.com/NixOS/nixpkgs/issues/568619) CVE-2026-103399 (https://github.com/NixOS/nixpkgs/issues/569071) --- pkgs/by-name/li/libsoup_3/package.nix | 85 ++------------------------- 1 file changed, 4 insertions(+), 81 deletions(-) diff --git a/pkgs/by-name/li/libsoup_3/package.nix b/pkgs/by-name/li/libsoup_3/package.nix index 872dfff315aa..aca894fafc34 100644 --- a/pkgs/by-name/li/libsoup_3/package.nix +++ b/pkgs/by-name/li/libsoup_3/package.nix @@ -2,7 +2,6 @@ stdenv, lib, fetchurl, - fetchpatch, glib, meson, ninja, @@ -21,11 +20,12 @@ gi-docgen, brotli, libnghttp2, + zstd, }: stdenv.mkDerivation (finalAttrs: { pname = "libsoup"; - version = "3.6.6"; + version = "3.8.0"; outputs = [ "out" @@ -35,87 +35,9 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/libsoup/${lib.versions.majorMinor finalAttrs.version}/libsoup-${finalAttrs.version}.tar.xz"; - hash = "sha256-Ue0K4G+dWkD0Af9Fni5fZS+aUQt3MOE1nuZtFNSHJ0A="; + hash = "sha256-u/CPo+A6iMMaPSeg2Hy0IulJDy0I4UkhEQPfbWOKIjg="; }; - patches = [ - (fetchpatch { - name = "CVE-2026-1539.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/98c1285d9d78662c38bf14b4a128af01ccfdb446.patch"; - hash = "sha256-gEqCeGx49/egPlMcvmOTslszJb/FlVlw+BhQznr5sv0="; - }) - (fetchpatch { - name = "CVE-2026-0719.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/1972635264f1d9ab1823c8b6becf921b4125b513.patch"; - hash = "sha256-k7inbIk0HyijAtTWXFxJYfDTDBif/izWrsYQmdg7z4A="; - }) - (fetchpatch { - name = "CVE-2026-12478.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/303256edac53bd9321fb6ec61924ea82f04ed284.patch"; - hash = "sha256-83teXanQTc6MC5/KBtfz0zgDjatSeiomIbmTFelc3d0="; - }) - (fetchpatch { - name = "CVE-2026-6324.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/96ac392b444d01bd5de1d1276b187c3ed49d048c.patch"; - hash = "sha256-Y4MzqjroDnUFgDd9NRW/bHRRjWaSphB5dU5DnMdIG6I="; - }) - (fetchpatch { - name = "Regression-fix-after-CVE-2026-6324-fix.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/538.patch"; - hash = "sha256-v5xvd7XLHCROeec2bid/5V7Livd1uMHki39Oi+OokLg="; - }) - (fetchpatch { - name = "CVE-2026-5119.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/b0626fff8538e3dd4a52f148d91c8348d51d64d1.patch"; - hash = "sha256-fLTmSp+Z8ZEVbqiaSOjG1iNhg16FS5ul8fP9y0uBeqY="; - }) - (fetchpatch { - name = "CVE-2026-4271.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/489affa74c8a229b8a4dd541710d4a5debedb7b4.patch"; - hash = "sha256-XuFJMHtAiQiJ26KQ51JDQdJ/NdVkuccZCHQMOyzzdF0="; - }) - (fetchpatch { - name = "CVE-2026-2708.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/e032d3e9b0a27d10597398023532dd8f9b6654cf.patch"; - hash = "sha256-r30VFpkOqJRiEhl63uavmKecbk8tpTuCvL9YbIozyZg="; - }) - (fetchpatch { - name = "CVE-2026-15711.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/60aa1ce2bdc7bb5da33be9062f50bcec7db67fca.patch"; - hash = "sha256-13fU7zuzkb7wIH3BxylBaVyw6s/X6f4/ji9yYqYIcVg="; - }) - (fetchpatch { - name = "CVE-2026-12548.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37.patch"; - hash = "sha256-eDsYtL6NHyouaVEHptZy2Gy/34guZJA7LUtj+YgWWQE="; - }) - (fetchpatch { - name = "CVE-2026-12549.patch"; # Also: CVE-2026-77014, CVE-2026-77680 - url = "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550.patch"; - hash = "sha256-Dpd1qyJlIqNp6MzqyCKQ6anQr887e4J3CAGXEyzQOYU="; - }) - (fetchpatch { - name = "CVE-2026-15713.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/24fb645fa949ece7d7e10363b77cf2d5fa2c2469.patch"; - hash = "sha256-TdWCOo2QnCnTbV0dPk4iGnNuwZO+LKSH1YFp2XAenwY="; - }) - (fetchpatch { - name = "CVE-2026-15712.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/3a6fb56a0cba42d11f5fd1db6dedcc7c2e92757b.patch"; - hash = "sha256-IPYr77720+LOi3fp+x2M4MTKOm62As0dh8lZ5hKsuTU="; - }) - (fetchpatch { - name = "CVE-2026-15714.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/79a52cadc490360e249cc2b23038d532b44dbf23.patch"; - hash = "sha256-p5J1QlfU+/be5YVahVTKt2QsxlRttrf62AYOa1QrwEo="; - }) - (fetchpatch { - name = "CVE-2026-85534.patch"; - url = "https://gitlab.gnome.org/GNOME/libsoup/-/commit/5f656cd97b8a6f4a5b8b7a30efb7c2cc8ef498fb.patch"; - hash = "sha256-DD5HO+ZCn9Q/lVWWG9WnTBSeOe37Y3GD4dvsP4YuCLI="; - }) - ]; - depsBuildBuild = [ pkg-config ]; @@ -139,6 +61,7 @@ stdenv.mkDerivation (finalAttrs: { glib.out brotli libnghttp2 + zstd ] ++ lib.optionals stdenv.hostPlatform.isLinux [ libsysprof-capture