REDHAT-BUG-2359343: High severity libsoup vulnerability
Published Apr 14, 2025
·Updated
libsoup's HTTP/2 server doesn't fully validate the values of the pseudo-headers :scheme, :authority, and :path. A client may crash the server by sending a malicious HTTP request.
Affected Software
1 affected component
Gnome libsoup
Event History
Apr 14, 2025
Data Sourced
via Red Hat·01:36 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2359343?
The severity of REDHAT-BUG-2359343 is considered critical due to potential server crashes caused by malicious HTTP requests.
2
How do I fix REDHAT-BUG-2359343?
To fix REDHAT-BUG-2359343, update to the latest patched version of libsoup that addresses the pseudo-header validation issues.
3
What software is affected by REDHAT-BUG-2359343?
The affected software for REDHAT-BUG-2359343 is GNOME libsoup.
4
What are the consequences of not addressing REDHAT-BUG-2359343?
Not addressing REDHAT-BUG-2359343 may leave your server vulnerable to crashes from malicious HTTP requests.
5
Can REDHAT-BUG-2359343 be exploited remotely?
Yes, REDHAT-BUG-2359343 can be exploited remotely through crafted HTTP/2 requests sent to the server.