﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21575	Fix several CVEs in libsoup2 (make patch for 12.3 users, and drop)	Douglas R. Reno	Douglas R. Reno	"(Thanks to Joe Locash for the report to me privately, more information just became available today so we can now act on this)

Several of the CVEs fixed in libsoup3 are also applicable to libsoup2. I want to drop this package and libgdata at the end of this release cycle unless libgdata gets adapted for libsoup3, but for now we should patch it for users who have libsoup2 installed.

Debian has applied patches at https://sources.debian.org/patches/libsoup2.4/2.74.3-10.1

CVEs include:

- CVE-2024-52530: 7.5 High, HTTP Request Smuggling
- CVE-2024-52531: 8.4 High, remote code execution through a buffer overflow
- CVE-2024-52532: 7.5 High, remotely exploitable denial of service
- CVE-2025-2784: 7.0 High, 1-byte buffer overread, realistically a remotely exploitable denial of service
- CVE-2025-32050: 5.9 Medium, remotely exploitable denial of service
- CVE-2025-32052: 6.5 Medium, remotely exploitable denial of service
- CVE-2025-32053: 6.5 Medium, remotely exploitable denial of service
- CVE-2025-32906: 7.5 High, allows users to remotely crash HTTP servers
- CVE-2025-32909: 6.5 Medium, remotely exploitable denial of service
- CVE-2025-32910: 6.5 Medium, remotely exploitable denial of service
- CVE-2025-32911: 9.0 Critical, remotely exploitable issue that allows for memory corruption
- CVE-2025-32912: 6.5 Medium, remotely exploitable denial of service
- CVE-2025-32914: 7.4 High, remotely exploitable out of bounds read
- CVE-2025-46420: 6.5 Medium, remotely exploitable denial of service due to memory leak"	enhancement	closed	high	12.4	BOOK	git	medium	fixed		
