[ALSA-2025:7436] Important: libsoup security update
Type:
security
Severity:
important
Release date:
2025-05-21
Description:
The libsoup packages provide an HTTP client and server library for GNOME. Security Fix(es): * libsoup: Integer overflow in append_param_quoted (CVE-2025-32050) * libsoup: Heap buffer overflow in sniff_unknown() (CVE-2025-32052) * libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() (CVE-2025-32053) * libsoup: Out of bounds reads in soup_headers_parse_request() (CVE-2025-32906) * libsoup: Denial of service in server when client requests a large amount of overlapping ranges with Range header (CVE-2025-32907) * libsoup: Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value (CVE-2025-32911) * libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header (CVE-2025-32913) * libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421) * libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c (CVE-2025-46420) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libsoup-devel-2.72.0-10.el9_6.1.aarch64.rpm 7313928c769478db597e3c31533ff2ff9cc94f2360cfb7a608c5d13ad30e79eb
aarch64 libsoup-2.72.0-10.el9_6.1.aarch64.rpm e3f1979fde261863b7bfd59454b2091709236577854119e13ab3ba42855dbfb0
i686 libsoup-devel-2.72.0-10.el9_6.1.i686.rpm 0f31b1846118dbd06b7aa1e86d0f5b36c9b0ec888b18a6c1c4e79a8f13d3d5de
i686 libsoup-2.72.0-10.el9_6.1.i686.rpm 37cf9a7666000de531ee16ab0554e472d72ac0e3d683e28c1b5ec8b7980ee835
ppc64le libsoup-2.72.0-10.el9_6.1.ppc64le.rpm 0672a8ff1851431d6fb638097f606c985bbf1c62d54c9dd0231bba195a4b0910
ppc64le libsoup-devel-2.72.0-10.el9_6.1.ppc64le.rpm a7266227e284e6ae7af8210826f71353be320749ff9982f641c1f4d563839d4e
s390x libsoup-2.72.0-10.el9_6.1.s390x.rpm a71c9c626bb96f1502b5358cb212db3ea6a0ee416fe0e4a25795867b5fcb89a0
s390x libsoup-devel-2.72.0-10.el9_6.1.s390x.rpm f66219d4cdd315b9265f2451ff75c4120514939c869eb441c3be576e37660fc6
x86_64 libsoup-devel-2.72.0-10.el9_6.1.x86_64.rpm 1bf9e97c6fc34e4efada5e603b9d5488dc6e5e27ea546c71ca56f9928aa5df57
x86_64 libsoup-2.72.0-10.el9_6.1.x86_64.rpm f9de877bb6b0ae7be375447f5d0aeffa2e712e734918cbe2d60e7c9a405d4d56
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.