RHSA-2025:8482: Important: libsoup security update
Important: libsoup security update
Other sources
The libsoup packages provide an HTTP client and server library for GNOME.Security Fix(es): libsoup: Heap buffer over-read in skipinsignificantspace when sniffing content (CVE-2025-2784) libsoup: Denial of Service attack to websocket server (CVE-2025-32049) libsoup: OOB Read on libsoup through function "soupmultipartnewfrommessage" in soup-multipart.c leads to crash or exit of process (CVE-2025-32914) libsoup: Integer Underflow in soupmultipartnewfrommessage() Leading to Denial of Service in libsoup (CVE-2025-4948) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities are addressed in RHSA-2025:8482?
RHSA-2025:8482 addresses a heap buffer over-read in `skip_insignificant_space` and potential denial of service issues in libsoup.
What is the severity level of RHSA-2025:8482?
The severity level of RHSA-2025:8482 is classified as important.
How do I resolve the issues outlined in RHSA-2025:8482?
To resolve the issues in RHSA-2025:8482, update the libsoup package to version 2.62.3-2.el8_6.5.
Which operating systems are affected by RHSA-2025:8482?
RHSA-2025:8482 affects Red Hat Enterprise Linux Server and its variants.
Is there a specific package version required to fix RHSA-2025:8482?
Yes, the required package version to fix RHSA-2025:8482 is libsoup 2.62.3-2.el8_6.5.