CVE-2025-32053: Libsoup: heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space()
A flaw was found in libsoup. A vulnerability in snifffeedorhtml() and skipinsignificantspace() functions may lead to a heap buffer over-read.
Other sources
libsoup prior to version 3.6.1 is vulnerable to heap buffer over-reads in the content sniffer's snifffeedorhtml() and skipinsignificantspace() functions. libsoup clients may read out of bounds in response to a crafted HTTP response sent by an HTTP server.
— Red Hat
Libsoup: heap buffer overflows in snifffeedorhtml() and skipinsignificantspace()
— Microsoft
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup2.4to a version that resolves this vulnerability.Fixed in 2.74.3-10 - Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.5-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-6 - Upgrade
Upgrade
libsoupto a version that resolves this vulnerability.Fixed in 3.6.1 - Compensating control
Mitigate exposure by not using untrusted HTTP servers or by limiting outbound HTTP access (e.g., via network controls/egress filtering) so clients are not exposed to crafted HTTP responses that trigger the heap buffer over-read.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32053?
CVE-2025-32053 has been classified as a moderate severity vulnerability due to the potential for heap buffer over-reads.
How do I fix CVE-2025-32053?
To fix CVE-2025-32053, upgrade to libsoup version 3.6.1 or later.
What functions are affected by CVE-2025-32053?
CVE-2025-32053 affects the sniff_feed_or_html() and skip_insignificant_space() functions within libsoup.
Which versions of libsoup are vulnerable to CVE-2025-32053?
Libsoup versions prior to 3.6.1 are vulnerable to CVE-2025-32053.
Who is affected by CVE-2025-32053?
Users and applications utilizing vulnerable versions of libsoup prior to 3.6.1 may be affected by CVE-2025-32053.