[ALSA-2025:8128] Important: libsoup3 security update
Type:
security
Severity:
important
Release date:
2025-05-29
Description:
Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it), but the SOAP parts were removed long ago. Security Fix(es): * libsoup: Denial of Service attack to websocket server (CVE-2025-32049) * libsoup: Denial of service in server when client requests a large amount of overlapping ranges with Range header (CVE-2025-32907) * libsoup: Cookie domain validation bypass via uppercase characters in libsoup (CVE-2025-4035) * libsoup: Integer Underflow in soup_multipart_new_from_message() Leading to Denial of Service in libsoup (CVE-2025-4948) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libsoup3-3.6.5-3.el10_0.6.aarch64.rpm 4363d0b487372b1e1375fcc25b9fdca56f321a3a73b38f01cca6e46eb34a6001
aarch64 libsoup3-devel-3.6.5-3.el10_0.6.aarch64.rpm 5ba6ceb09f8b5b5e37ee6061bc10d7bf022d37353c1d0d09e30965dc28950f7c
noarch libsoup3-doc-3.6.5-3.el10_0.6.noarch.rpm 68ccea520221810f3995b0161a9cfb4ea6e01c8fddff9fcff68d00336c30a9de
ppc64le libsoup3-3.6.5-3.el10_0.6.ppc64le.rpm c292a5da5b49f86a39966310042dc90c58dc0064fae2bf485764a531b238ddff
ppc64le libsoup3-devel-3.6.5-3.el10_0.6.ppc64le.rpm d4017c55f98d9d90370b5695ea2cfdd99f0ca4f08eaabd7c9eddea41932e597d
s390x libsoup3-devel-3.6.5-3.el10_0.6.s390x.rpm 772e6a436ea9e3a247497765401abe7df0aa084cd9b7c086f518df39cb6e2342
s390x libsoup3-3.6.5-3.el10_0.6.s390x.rpm af3ebaf8b85b039bfe33ce3802e0202690f16e1a30f77fa95512edaf85d04d2e
x86_64 libsoup3-3.6.5-3.el10_0.6.x86_64.rpm 5c3ab84c3fe3cfac26c5e3f5ded177268efbda39848b1163a8d33fd578984a2f
x86_64 libsoup3-devel-3.6.5-3.el10_0.6.x86_64.rpm b3eb92a3ffbb7c1e2856dee87d65dbbd68b79a586f58bd4aee048971f1aed57f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.