CVE-2025-32051: Libsoup: segmentation fault when parsing malformed data uri
A flaw was found in libsoup. The libsoup soupuridecodedatauri() function may crash when processing malformed data URI. This flaw allows an attacker to cause a denial of service (DoS).
Other sources
Libsoup: segmentation fault when parsing malformed data uri
— Microsoft
libsoup's soupuridecodedatauri() function, prior to libsoup 3.6.1, may crash when processing a malformed data URI, resulting in denial of service.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup2.4to a version that resolves this vulnerability.Fixed in 2.72.0-2Fixed in 2.72.0-2+deb11u1Fixed in 2.74.3-1+deb12u1Fixed in 2.74.3-9 - Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.5-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-5 - Upgrade
Upgrade
libsoupto a version that resolves this vulnerability.Fixed in 3.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32051?
CVE-2025-32051 is classified as a denial of service (DoS) vulnerability.
How do I fix CVE-2025-32051?
To fix CVE-2025-32051, upgrade libsoup to version 3.6.1 or later.
What causes CVE-2025-32051?
CVE-2025-32051 is caused by a flaw in the soup_uri_decode_data_uri() function that can crash when processing malformed data URIs.
Which versions of libsoup are affected by CVE-2025-32051?
Versions of libsoup prior to 3.6.1 are affected by CVE-2025-32051.
Can CVE-2025-32051 be exploited remotely?
Yes, CVE-2025-32051 can be exploited remotely, allowing attackers to cause a denial of service.