[ALSA-2025:20959] Important: libsoup security update
Type:
security
Severity:
important
Release date:
2025-11-19
Description:
The libsoup packages provide an HTTP client and server library for GNOME. Security Fix(es): * libsoup: Integer Overflow in Cookie Expiration Date Handling in libsoup (CVE-2025-4945) * libsoup: Out-of-Bounds Read in Cookie Date Handling of libsoup HTTP Library (CVE-2025-11021) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libsoup-2.72.0-12.el9_7.1.aarch64.rpm 0998ab68d255ae0f52f435f3b39e612c40dcc33ebeee7a25c50e7fd47fac76e2
aarch64 libsoup-devel-2.72.0-12.el9_7.1.aarch64.rpm 514b4b1b398a469cb12fbde04ab433448ddaf70b8f8d55b9d59c785dc18d0804
i686 libsoup-2.72.0-12.el9_7.1.i686.rpm 18cd18f4a7b6d24aa192d2896563d6c52e4c82f5a477a117d6013da6762c9e6a
i686 libsoup-devel-2.72.0-12.el9_7.1.i686.rpm 4908b29611e002c7f3e4dc1237f42145da899c5c6c90f2dffd29813a2ed01b66
ppc64le libsoup-2.72.0-12.el9_7.1.ppc64le.rpm 075a10d9f149e1ec3ea3b9ef535d5eb5def637cb6b12dc61a116a1588663daed
ppc64le libsoup-devel-2.72.0-12.el9_7.1.ppc64le.rpm 70e8dee55a066186ff463296af858947656800227ac8d1042093d6106f2c8810
s390x libsoup-2.72.0-12.el9_7.1.s390x.rpm bf7b69aeaf7aedfda372130c6de4100a22ca0c23d903bdf035d59343b1c8cf66
s390x libsoup-devel-2.72.0-12.el9_7.1.s390x.rpm f77b8a5c14e3139c86cadd263a0e50933c1b94cdb45493a0e3e7ff72e0744c48
x86_64 libsoup-2.72.0-12.el9_7.1.x86_64.rpm 85678d82f1bbc68efa4061e9f5e1e80c84a78a2c23348bb41c42ca741603fdc6
x86_64 libsoup-devel-2.72.0-12.el9_7.1.x86_64.rpm fd4048e286f01050db0f56f2e1c0e1fff4623ab9510ea243a5301bd818e8b0b8
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.