CVE-2024-52532: High severity Gnome libsoup vulnerability
GNOME libsoup before 3.6.1 has an infinite loop and memory consumption. during the reading of certain patterns of WebSocket data from clients.
Other sources
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52532?
CVE-2024-52532 is classified as a medium severity vulnerability due to its potential to cause an infinite loop and high memory consumption.
How do I fix CVE-2024-52532?
To fix CVE-2024-52532, update GNOME libsoup to version 3.6.1-1 or later.
What versions of libsoup are affected by CVE-2024-52532?
CVE-2024-52532 affects versions of libsoup before 3.6.1 and specific versions of libsoup2.4 up to 2.74.3-8.
Is CVE-2024-52532 exploitable remotely?
Yes, CVE-2024-52532 is remotely exploitable since it involves handling WebSocket data from clients.
What are the potential impacts of CVE-2024-52532?
The potential impacts of CVE-2024-52532 include application crashes and excessive memory usage, leading to service denial.