[ALSA-2025:4560] Important: libsoup security update
Type:
security
Severity:
important
Release date:
2025-05-07
Description:
The libsoup packages provide an HTTP client and server library for GNOME. Security Fix(es): * libsoup: Integer overflow in append_param_quoted (CVE-2025-32050) * libsoup: Heap buffer overflow in sniff_unknown() (CVE-2025-32052) * libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() (CVE-2025-32053) * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906) * libsoup: Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value (CVE-2025-32911) * libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header (CVE-2025-32913) * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421) * libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c (CVE-2025-46420) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libsoup-devel-2.62.3-8.el8_10.aarch64.rpm 0a0bdcccf294b6c91a9c9363c689eace282e4994d36073cb53f94bc2946c6cbf
aarch64 libsoup-2.62.3-8.el8_10.aarch64.rpm d0b7c3ae83e31a33ea3df0bfadad5266d47801be7e98fba57c8483d11ca7acf1
i686 libsoup-2.62.3-8.el8_10.i686.rpm a6828ae57fbf07cdff197fcc926a6ed8c166244706a4b97d38f9944ce2c94388
i686 libsoup-devel-2.62.3-8.el8_10.i686.rpm c089797308fbcaf0dc26c08585ef2161d5f91b4e0f5d1a2bdef23cafb171bdc0
ppc64le libsoup-devel-2.62.3-8.el8_10.ppc64le.rpm 43f2c98b6c5dc9e8467d35c36d74dccf67dfcacb387183ff6bbb1b72234c8974
ppc64le libsoup-2.62.3-8.el8_10.ppc64le.rpm 5b5148c8baf3037393f550da33c6fe1de7b84964d33e796ae4a28cb4ecd70bbc
s390x libsoup-devel-2.62.3-8.el8_10.s390x.rpm 9093546354277d55fbfe91f7e072fdb9d1f3c11ed8b7807c6709264ec0a170ad
s390x libsoup-2.62.3-8.el8_10.s390x.rpm b2e2dc62613044719160fbc13407dca700e215578e66bc0d06808260f4832fc5
x86_64 libsoup-2.62.3-8.el8_10.x86_64.rpm 3ffeb93e9ade5b681e7e45855e09a2f22d106f031afbef88b880dca957b8ebdd
x86_64 libsoup-devel-2.62.3-8.el8_10.x86_64.rpm de11992ac9b330741966d41d64da3458a37016097871bcc75f52a5cd664dc2e2
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.