USN-7127-1: libsoup3 vulnerabilities
It was discovered that libsoup ignored certain characters at the end of header names. A remote attacker could possibly use this issue to perform a HTTP request smuggling attack. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-52530) It was discovered that libsoup did not correctly handle memory while performing UTF-8 conversions. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-52531) It was discovered that libsoup could enter an infinite loop when reading certain websocket data. An attacker could possibly use this issue to cause a denial of service. (CVE-2024-52532)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7127-1?
The severity of USN-7127-1 is classified as critical due to the potential for HTTP request smuggling attacks.
How do I fix USN-7127-1?
To fix USN-7127-1, update the libsoup-3.0-0 package to version 3.6.0-2ubuntu0.1 or later for Ubuntu 24.10 and to version 3.4.4-5ubuntu0.1 or later for Ubuntu 24.04.
Which systems are affected by USN-7127-1?
USN-7127-1 affects Ubuntu 22.04 LTS and Ubuntu 24.04 LTS installations running specific versions of libsoup-3.0-0.
What type of vulnerability is described in USN-7127-1?
The vulnerability described in USN-7127-1 is an improper input validation issue that could allow HTTP request smuggling.
Is there a workaround for USN-7127-1?
There are no specific workarounds for USN-7127-1, so updating to the patched versions is the recommended solution.