USN-7490-2: libsoup regression
USN-7490-1 fixed vulnerabilities in libsoup. It was discovered that the fix for CVE-2025-32912 was incomplete. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Tan Wei Chong discovered that libsoup incorrectly handled memory when parsing HTTP request headers. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service. (CVE-2025-32906) Alon Zahavi discovered that libsoup incorrectly parsed video files. An attacker could possibly use this issue to send a maliciously crafted HTTP response back to the client, causing a denial of service, or leading to undefined behavior. (CVE-2025-32909) Jan Różański discovered that libsoup incorrectly handled memory when parsing authentication headers. An attacker could possibly use this issue to send a maliciously crafted HTTP response back to the client, causing a denial of service. (CVE-2025-32910, CVE-2025-32912) It was discovered that libsoup incorrectly handled data in the hash table data type. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service or remote code execution. (CVE-2025-32911) Jan Różański discovered that libsoup incorrectly handled memory when parsing the content disposition HTTP header. An attacker could possibly use this issue to send maliciously crafted data to a client or server, causing a denial of service. (CVE-2025-32913) Alon Zahavi discovered that libsoup incorrectly handled memory when parsing HTTP requests. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service or obtaining sensitive information. (CVE-2025-32914) It was discovered that libsoup incorrectly handled memory when parsing quality-list headers. An attacker could possibly use this issue to send a maliciously crafted HTTP request to the server, causing a denial of service. (CVE-2025-46420) Jan Różański discovered that libsoup did not strip authorization information upon redirects. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-46421)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7490-2?
USN-7490-2 addresses an incomplete fix for a previously identified vulnerability, indicating a medium severity level.
How do I fix USN-7490-2?
To fix USN-7490-2, update libsoup to version 2.74.3-10ubuntu0.2 or the appropriate patched version for your Ubuntu release.
What products are affected by USN-7490-2?
USN-7490-2 affects multiple versions of Ubuntu, including 25.04, 24.10, 24.04, 22.04, 20.04, 18.04, and 16.04 with specific libsoup versions.
What are the implications of the vulnerability fixed by USN-7490-2?
The vulnerability fixed by USN-7490-2 could lead to memory handling issues when libsoup parses, potentially exposing systems to further exploits.
Who is responsible for the discovery of the vulnerability fixed by USN-7490-2?
The vulnerability addressed in USN-7490-2 was discovered by security researcher Tan Wei Chong.