RHSA-2025:8252: Important: libsoup security update
Important: libsoup security update
Other sources
The libsoup packages provide an HTTP client and server library for GNOME.Security Fix(es): libsoup: Heap buffer over-read in skipinsignificantspace when sniffing content (CVE-2025-2784) libsoup: Denial of Service attack to websocket server (CVE-2025-32049) libsoup: OOB Read on libsoup through function "soupmultipartnewfrommessage" in soup-multipart.c leads to crash or exit of process (CVE-2025-32914) libsoup: Integer Underflow in soupmultipartnewfrommessage() Leading to Denial of Service in libsoup (CVE-2025-4948) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerability is addressed in RHSA-2025:8252?
RHSA-2025:8252 addresses a heap buffer over-read vulnerability in the `skip_insignificant_space` function in libsoup (CVE-2025-2784).
What is the severity level of the vulnerability in RHSA-2025:8252?
The severity of the vulnerability addressed in RHSA-2025:8252 is categorized as important.
How do I update my system to fix RHSA-2025:8252?
To fix RHSA-2025:8252, update the libsoup package to version 2.62.3-3.el8_8.5 or later.
What new features or fixes are included in the update for RHSA-2025:8252?
The update in RHSA-2025:8252 includes fixes for security vulnerabilities but does not introduce new features.
Which systems are affected by the vulnerability in RHSA-2025:8252?
Systems running versions of libsoup prior to 2.62.3-3.el8_8.5, particularly on Red Hat Enterprise Linux distributions, are affected by RHSA-2025:8252.