RHSA-2025:8480: Important: libsoup security update
Important: libsoup security update
Other sources
The libsoup packages provide an HTTP client and server library for GNOME.<br>Security Fix(es):<br><li> libsoup: Heap buffer over-read in skipinsignificantspace when sniffing content (CVE-2025-2784)</li> <li> libsoup: Denial of Service attack to websocket server (CVE-2025-32049)</li> <li> libsoup: OOB Read on libsoup through function "soupmultipartnewfrommessage" in soup-multipart.c leads to crash or exit of process (CVE-2025-32914)</li> <li> libsoup: Integer Underflow in soupmultipartnewfrommessage() Leading to Denial of Service in libsoup (CVE-2025-4948)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8480?
The severity of RHSA-2025:8480 is categorized as Important.
What vulnerabilities are addressed in RHSA-2025:8480?
RHSA-2025:8480 addresses a heap buffer over-read leading to potential denial of service, specifically CVE-2025-2784.
How do I fix RHSA-2025:8480?
To fix RHSA-2025:8480, update the libsoup package to version 2.62.3-1.el8_2.5.
Which software versions are affected by RHSA-2025:8480?
Affected software versions include libsoup and its variants for Red Hat Enterprise Linux Server versions prior to 2.62.3-1.el8_2.5.
What is the recommended action after applying the fix for RHSA-2025:8480?
After applying the fix for RHSA-2025:8480, it is recommended to restart any affected services or applications.