CVE-2025-32910: Libsoup: null pointer deference on libsoup via /auth/soup-auth-digest.c through "soup_auth_digest_authenticate" on client when server omits the "realm" parameter in an unauthorized response with digest authentication
A flaw was found in libsoup, where soupauthdigestauthenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.
Other sources
libsoup prior to version 3.6.3 is vulnerable to a null pointer dereference in soupauthdigestauthenticate(). A malicious HTTP server may cause the libsoup client to crash.
— Red Hat
Libsoup: null pointer deference on libsoup via /auth/soup-auth-digest.c through "soupauthdigestauthenticate" on client when server omits the "realm" parameter in an unauthorized response with digest authentication
— Microsoft
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libsoup2.4to a version that resolves this vulnerability.Fixed in 2.72.0-2+deb11u2Fixed in 2.74.3-10.1 - Upgrade
Upgrade
debian/libsoup3to a version that resolves this vulnerability.Fixed in 3.6.5-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.4.4-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.0.4-7 - Upgrade
Upgrade
libsoupto a version that resolves this vulnerability.Fixed in 3.6.3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32910?
CVE-2025-32910 has a medium severity rating as it can lead to a crash of the libsoup client.
How do I fix CVE-2025-32910?
To fix CVE-2025-32910, upgrade libsoup to version 3.6.3 or later.
Which versions of libsoup are affected by CVE-2025-32910?
Versions of libsoup prior to 3.6.3 are affected by CVE-2025-32910.
What causes the CVE-2025-32910 vulnerability?
CVE-2025-32910 is caused by a NULL pointer dereference in the soup_auth_digest_authenticate() function.
What impact does CVE-2025-32910 have on systems using libsoup?
The impact of CVE-2025-32910 is that it may cause the libsoup client to crash.