RHSA-2025:8481: Important: libsoup security update
Important: libsoup security update
Other sources
The libsoup packages provide an HTTP client and server library for GNOME.<br>Security Fix(es):<br><li> libsoup: Heap buffer over-read in skipinsignificantspace when sniffing content (CVE-2025-2784)</li> <li> libsoup: Denial of Service attack to websocket server (CVE-2025-32049)</li> <li> libsoup: OOB Read on libsoup through function "soupmultipartnewfrommessage" in soup-multipart.c leads to crash or exit of process (CVE-2025-32914)</li> <li> libsoup: Integer Underflow in soupmultipartnewfrommessage() Leading to Denial of Service in libsoup (CVE-2025-4948)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8481?
The severity of RHSA-2025:8481 is classified as Important.
How do I fix RHSA-2025:8481?
To fix RHSA-2025:8481, update the libsoup package to version 2.72.0-8.el9_0.5 or later.
What vulnerabilities are addressed in RHSA-2025:8481?
RHSA-2025:8481 addresses a heap buffer over-read in `skip_insignificant_space` and potential denial of service vulnerabilities.
Which systems are affected by RHSA-2025:8481?
RHSA-2025:8481 affects multiple versions of Red Hat Enterprise Linux, including support for Power LE, ARM 64, x86_64, and IBM z Systems.
Is there any risk associated with not applying RHSA-2025:8481?
Yes, not applying RHSA-2025:8481 may leave systems vulnerable to information leakage and denial of service attacks.