CVE-2025-32050: Libsoup: integer overflow in append_param_quoted
A flaw was found in libsoup. The libsoup appendparamquoted() function may contain an overflow bug resulting in a buffer under-read.
Other sources
Libsoup: integer overflow in appendparamquoted
— Microsoft
libsoup's appendparamquoted() function, prior to libsoup 3.6.1, contains an integer overflow bug resulting in buffer under-read, which may be triggered by sending an extremely large HTTP request to the libsoup server.
— Red Hat
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup2.4to a version that resolves this vulnerability.Fixed in 2.74.3-10 - Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.5-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-5 - Upgrade
Upgrade
libsoupto a version that resolves this vulnerability.Fixed in 3.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32050?
CVE-2025-32050 has been classified with a high severity due to the potential for exploitation leading to buffer under-read vulnerabilities.
How do I fix CVE-2025-32050?
To fix CVE-2025-32050, upgrade libsoup to version 3.6.1 or later, which resolves the overflow bug.
What software is affected by CVE-2025-32050?
CVE-2025-32050 affects libsoup versions prior to 3.6.1.
What kind of vulnerability is CVE-2025-32050?
CVE-2025-32050 is an integer overflow vulnerability that may lead to buffer under-read issues in the libsoup library.
What is the potential impact of exploiting CVE-2025-32050?
Exploiting CVE-2025-32050 could allow an attacker to manipulate data processing functions, which may lead to unintended behavior in applications relying on libsoup.