Opened 17 months ago

Closed 11 months ago

Last modified 8 months ago

#21576 closed enhancement (fixed)

Fix CVE-2025-12105, CVE-2025-4948, CVE-2025-4945, CVE-2025-4969, CVE-2025-4476, CVE-2025-32914, CVE-2025-32908, and CVE-2025-32907 in libsoup3

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Four new security vulnerabilities have been found in libsoup3 that we should patch, alongside those in libsoup2.

Patches can be found at ​https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/451, ​https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/453, ​https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/450, ​https://gitlab.gnome.org/GNOME/libsoup/-/commit/c4c4eedbb71cba15075ac55a171aeac27e7bfd45 (for CVE-2025-32049), and ​https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/452

While these are only denial of service vulnerabilities, they can both be exploited remotely. When I file the security advisory for this, I'll also need to factor in bugs that were later assigned CVEs fixed in 3.6.5.

Thank you again to Joe Locash for the pointers on this, and to upstream for making more information available so we can act on it.

  • CVE-2025-32914: 7.4 High, remotely exploitable out of bounds read
  • CVE-2025-32908: 7.4 High, remotely exploitable crash
  • CVE-2025-32049: 7.5 High, remotely exploitable crash
  • CVE-2025-32907: 5.3 Medium, excessive memory consumption

The security vulnerabilities fixed in previous versions that we need to document are:

  • CVE-2025-32050 - Integer overflow in append_param_quoted Date Fixed: November 22, 2024
  • CVE-2025-32051 - Segmentation fault when parsing malformed data URI Date Fixed: November 22, 2024
  • CVE-2025-32052 - Heap buffer over-read in soup-content-sniffer.c:sniff_unknown() Date Fixed: November 22, 2024
  • CVE-2025-32053 - Heap buffer over-read in soup-content-sniffer.c:sniff_feed_or_html() and soup-content-sniffer.c:skip_insignificant_space() Date Fixed: November 22, 2024
  • CVE-2025-32906 - Out of bounds reads in soup_headers_parse_request() Date Fixed: February 24, 2025
  • CVE-2025-32909 - NULL Pointer Dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.c Date Fixed: January 8, 2025
  • CVE-2025-32910 - Null pointer deference on libsoup via /auth/soup-auth-digest.c through "soup_auth_digest_authenticate" on client when server omits the "realm" parameter in an Unauthorized response with Digest authentication Date Fixed: January 10, 2025
  • CVE-2025-32911 - Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value Date Fixed: January 8, 2025
  • CVE-2025-32912 - NULL pointer dereference in client when server omits the "nonce" parameter in an Unauthorized response with Digest authentication Date Fixed: February 8, 2025
  • CVE-2025-32913 - NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header Date Fixed: January 8, 2025

Change History (19)

comment:1 by Douglas R. Reno, 17 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Xi Ruoyao, 17 months ago

It looks like there are more impending:

comment:3 by Xi Ruoyao, 17 months ago

Also:

Last edited 17 months ago by Xi Ruoyao (previous) (diff)

in reply to:  3 ; comment:4 by Xi Ruoyao, 17 months ago

Replying to Xi Ruoyao:

Also:

Oops, why the issues was created "1 months ago" while 3.6.5 already contains the fix?!

in reply to:  4 comment:5 by Douglas R. Reno, 17 months ago

Replying to Xi Ruoyao:

Replying to Xi Ruoyao:

Also:

Oops, why the issues was created "1 months ago" while 3.6.5 already contains the fix?!

It's been really annoying to track :(

comment:6 by Xi Ruoyao, 17 months ago

edited comment:4 to remove two three items already fixed in 3.6.5.

Last edited 17 months ago by Xi Ruoyao (previous) (diff)

comment:7 by Joe Locash, 17 months ago

Here's another:

​https://gitlab.gnome.org/GNOME/libsoup/-/issues/449 It's tagged as Security and a CVE was requested.

comment:9 by Douglas R. Reno, 17 months ago

Milestone: 12.4 → 99-Waiting
Summary: Fix CVE-2025-32914, CVE-2025-32908 CVE-2025-32049, and CVE-2025-32907 in libsoup3 → Fix CVE-2025-32914, CVE-2025-32908 CVE-2025-32049, and CVE-2025-32907 in libsoup3 (Wait for issues to stabilize)

We need to wait for this situation to stabilize. At least one of the MRs is still under active discussion and has some major issues.

I will still file an SA for 3.6.5 though

comment:10 by Douglas R. Reno, 17 months ago

Priority: elevated → normal

comment:11 by Douglas R. Reno, 17 months ago

SA-12.3-021 issued for libsoup3 issues that we have fixes for at this time.

comment:12 by pierre, 12 months ago

Not sure what "stabilize" mean here, since issues keep incoming... I browsed through closed issues containing "CVE" in their text, and with "fixed version" field of "not released" or "not fixed". Here are the results (most recent first, sorry):

I need to check that those are not already in 3.6.5, will possibly edit if so

comment:13 by Douglas R. Reno, 12 months ago

Milestone: 99-Waiting → 12.5
Priority: normal → high

At the time I was working on this last, there weren't any fixes for most of these. The ones you listed above were not resolved by 3.6.5. What I meant by stabilize at the time was having patches available...

I will get a patch together shortly for these!

  • CVE-2025-4948: 7.5 High, integer overflow leading to remotely exploitable denial of service
  • CVE-2025-4945: 3.7 Low, integer overflow leading to undefined behavior. This allows attackers to bypass cookie expiration logic, causing persistent or unintended cookie behavior.
  • CVE-2025-4969: 6.5 Medium, out-of-bounds read causing a crash or possibly information disclosure
  • CVE-2025-4476: 4.3 Medium, denial-of-service when processing a malformed header
  • CVE-2025-32914: 7.4 High, out-of-bounds read in soup_multipart_new_from_message()
  • CVE-2025-32908: 7.5 High, HTTP/2 server doesn't properly validate some values of pseudo-headers :scheme:,:authority:, and :path: which causes a denial of service
  • CVE-2025-32907: 5.3 Medium, resource consumption attack

comment:14 by pierre, 12 months ago

CVE-2025-32049 should not be solved very soon, because it seems to need an API change, that will be available in 3.8.x Other not fixed CVE's: CVE-2025-4035 (but seems there is a fix in epiphany), and CVE-2025-9901 ("low priority")

comment:15 by Douglas R. Reno, 12 months ago

It looks like Red Hat has fixes for the three listed above in RHEL, but they don't seem to be available in Fedora at least so we can't really get access to them. I would be willing to try the fix for CVE-2025-32049 on one of my systems though to see how it works.

The fix for CVE-2025-4035 is not in Epiphany-48.x, but is in 49.x. I'll make sure to mention that users should update to Epiphany-49.x to help guard against this vulnerability (but of course that's just one attack angle, it could get exploited in other applications as well)

We're also going to want to backport "soup-init: Use libdl instead of gmodule in soup2_is_loaded check" because it can cause deadlocks when libsoup is used with other libraries which also contend with GLib mutexes.

comment:16 by Douglas R. Reno, 11 months ago

An additional CVE fix needs to be included - CVE-2025-12105. ​https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/481

CVE-2025-4035 is definitely best fixed via Epiphany. I'll update that ticket shortly to mention that it's security sensitive.

There is also ​https://gitlab.gnome.org/GNOME/libsoup/-/issues/446 - which hasn't been assigned a CVE, but was marked as a security report! I've included the patch from that which is ​https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/459

CVE-2025-9901 still doesn't appear to be resolved anywhere, and is still seen as relatively low priority. It's interesting though that Debian mentions that it could result in confidentiality problems in some environments.

​https://gitlab.gnome.org/GNOME/libsoup/-/issues/469 has no fix but is noted that the impact is minimal to users (and no CVE was assigned)

​https://gitlab.gnome.org/GNOME/libsoup/-/issues/471 has no fix but also has minimal impact, and relies on the attacker being able to view the system's logs.

​https://gitlab.gnome.org/GNOME/libsoup/-/issues/468 is new but no fixes are available at this time, it looks like with the upstream backlog that there hasn't been time to look at this one

There are four additional issues open that we will not be able to view until December and January. ​https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home is where I'm getting that information

The fix for CVE-2025-32049 is one that requires an API change, which also bumps the package version to 3.7.0. One of the developers has noted that a downstream fix exists that doesn't include the API change, but it appears to only be available in Red Hat Enterprise Linux, and I haven't been able to find any other distributions that are carrying it. I have it on my system, but I don't feel comfortable adding it in unless another distro carries it, especially due to the need for an API change.

On that note, we still need ​https://gitlab.gnome.org/GNOME/libsoup/-/commit/2316e56a5502ac4c41ef4ff56a3266e680aca129 to fix a deadlock problem.

At the end of the day, this patch will fix:

comment:17 by Douglas R. Reno, 11 months ago

Summary: Fix CVE-2025-32914, CVE-2025-32908 CVE-2025-32049, and CVE-2025-32907 in libsoup3 (Wait for issues to stabilize) → Fix CVE-2025-12105, CVE-2025-4948, CVE-2025-4945, CVE-2025-4969, CVE-2025-4476, CVE-2025-32914, CVE-2025-32908, and CVE-2025-32907 in libsoup3

comment:18 by Douglas R. Reno, 11 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 21a21cbc02736ad9e974de308f1f2c91da7e0af6

SA-12.4-034 issued

comment:19 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.