#21576 closed enhancement (fixed)
Fix CVE-2025-12105, CVE-2025-4948, CVE-2025-4945, CVE-2025-4969, CVE-2025-4476, CVE-2025-32914, CVE-2025-32908, and CVE-2025-32907 in libsoup3
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Four new security vulnerabilities have been found in libsoup3 that we should patch, alongside those in libsoup2.
Patches can be found at https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/451, https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/453, https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/450, https://gitlab.gnome.org/GNOME/libsoup/-/commit/c4c4eedbb71cba15075ac55a171aeac27e7bfd45 (for CVE-2025-32049), and https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/452
While these are only denial of service vulnerabilities, they can both be exploited remotely. When I file the security advisory for this, I'll also need to factor in bugs that were later assigned CVEs fixed in 3.6.5.
Thank you again to Joe Locash for the pointers on this, and to upstream for making more information available so we can act on it.
- CVE-2025-32914: 7.4 High, remotely exploitable out of bounds read
- CVE-2025-32908: 7.4 High, remotely exploitable crash
- CVE-2025-32049: 7.5 High, remotely exploitable crash
- CVE-2025-32907: 5.3 Medium, excessive memory consumption
The security vulnerabilities fixed in previous versions that we need to document are:
- CVE-2025-32050 - Integer overflow in append_param_quoted Date Fixed: November 22, 2024
- CVE-2025-32051 - Segmentation fault when parsing malformed data URI Date Fixed: November 22, 2024
- CVE-2025-32052 - Heap buffer over-read in soup-content-sniffer.c:sniff_unknown() Date Fixed: November 22, 2024
- CVE-2025-32053 - Heap buffer over-read in soup-content-sniffer.c:sniff_feed_or_html() and soup-content-sniffer.c:skip_insignificant_space() Date Fixed: November 22, 2024
- CVE-2025-32906 - Out of bounds reads in soup_headers_parse_request() Date Fixed: February 24, 2025
- CVE-2025-32909 - NULL Pointer Dereference on libsoup through function "sniff_mp4" in soup-content-sniffer.c Date Fixed: January 8, 2025
- CVE-2025-32910 - Null pointer deference on libsoup via /auth/soup-auth-digest.c through "soup_auth_digest_authenticate" on client when server omits the "realm" parameter in an Unauthorized response with Digest authentication Date Fixed: January 10, 2025
- CVE-2025-32911 - Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value Date Fixed: January 8, 2025
- CVE-2025-32912 - NULL pointer dereference in client when server omits the "nonce" parameter in an Unauthorized response with Digest authentication Date Fixed: February 8, 2025
- CVE-2025-32913 - NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header Date Fixed: January 8, 2025
Change History (19)
comment:1 by , 17 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 17 months ago
follow-up: 4 comment:3 by , 17 months ago
Also:
https://gitlab.gnome.org/GNOME/libsoup/-/issues/422 (CVE-2025-2784)https://gitlab.gnome.org/GNOME/libsoup/-/issues/401 (CVE-2024-52531)https://gitlab.gnome.org/GNOME/libsoup/-/issues/439 (CVE-2025-46421)- https://gitlab.gnome.org/GNOME/libsoup/-/issues/440 (CVE-2025-4476)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/446 (not sure if this is really a security issue, but it seems detected during the same event as those vulnerabilities)
follow-up: 5 comment:4 by , 17 months ago
Replying to Xi Ruoyao:
Also:
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/422 (CVE-2025-2784)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/401 (CVE-2024-52531)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/439 (CVE-2025-46421)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/440 (CVE-2025-4476)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/446 (not sure if this is really a security issue, but it seems detected during the same event as those vulnerabilities)
Oops, why the issues was created "1 months ago" while 3.6.5 already contains the fix?!
comment:5 by , 17 months ago
Replying to Xi Ruoyao:
Replying to Xi Ruoyao:
Also:
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/422 (CVE-2025-2784)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/401 (CVE-2024-52531)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/439 (CVE-2025-46421)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/440 (CVE-2025-4476)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/446 (not sure if this is really a security issue, but it seems detected during the same event as those vulnerabilities)
Oops, why the issues was created "1 months ago" while 3.6.5 already contains the fix?!
It's been really annoying to track :(
comment:7 by , 17 months ago
Here's another:
https://gitlab.gnome.org/GNOME/libsoup/-/issues/449 It's tagged as Security and a CVE was requested.
comment:8 by , 17 months ago
A couple more tickets were made visible recently. Here' a list of the open tickets I show:
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/390 (CVE-2025-32049)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/428 (CVE-2025-32907)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/443 (CVE-2025-4035)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/448 (CVE-2025-4945)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/447 (CVE-2025-4969)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/449 (CVE-2025-4948)
comment:9 by , 17 months ago
| Milestone: | 12.4 → 99-Waiting |
|---|---|
| Summary: | Fix CVE-2025-32914, CVE-2025-32908 CVE-2025-32049, and CVE-2025-32907 in libsoup3 → Fix CVE-2025-32914, CVE-2025-32908 CVE-2025-32049, and CVE-2025-32907 in libsoup3 (Wait for issues to stabilize) |
We need to wait for this situation to stabilize. At least one of the MRs is still under active discussion and has some major issues.
I will still file an SA for 3.6.5 though
comment:10 by , 17 months ago
| Priority: | elevated → normal |
|---|
comment:11 by , 17 months ago
SA-12.3-021 issued for libsoup3 issues that we have fixes for at this time.
comment:12 by , 12 months ago
Not sure what "stabilize" mean here, since issues keep incoming... I browsed through closed issues containing "CVE" in their text, and with "fixed version" field of "not released" or "not fixed". Here are the results (most recent first, sorry):
- CVE-2025-4948: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/463
- CVE-2025-4945: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/473
- CVE-2025-4969: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/467
- CVE-2025-4476: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/457
- CVE-2025-32914: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/450
- CVE-2025-32908: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/451 and https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/453
- CVE-2025-32907: Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/452
I need to check that those are not already in 3.6.5, will possibly edit if so
comment:13 by , 12 months ago
| Milestone: | 99-Waiting → 12.5 |
|---|---|
| Priority: | normal → high |
At the time I was working on this last, there weren't any fixes for most of these. The ones you listed above were not resolved by 3.6.5. What I meant by stabilize at the time was having patches available...
I will get a patch together shortly for these!
- CVE-2025-4948: 7.5 High, integer overflow leading to remotely exploitable denial of service
- CVE-2025-4945: 3.7 Low, integer overflow leading to undefined behavior. This allows attackers to bypass cookie expiration logic, causing persistent or unintended cookie behavior.
- CVE-2025-4969: 6.5 Medium, out-of-bounds read causing a crash or possibly information disclosure
- CVE-2025-4476: 4.3 Medium, denial-of-service when processing a malformed header
- CVE-2025-32914: 7.4 High, out-of-bounds read in soup_multipart_new_from_message()
- CVE-2025-32908: 7.5 High, HTTP/2 server doesn't properly validate some values of pseudo-headers :scheme:,:authority:, and :path: which causes a denial of service
- CVE-2025-32907: 5.3 Medium, resource consumption attack
comment:14 by , 12 months ago
CVE-2025-32049 should not be solved very soon, because it seems to need an API change, that will be available in 3.8.x Other not fixed CVE's: CVE-2025-4035 (but seems there is a fix in epiphany), and CVE-2025-9901 ("low priority")
comment:15 by , 12 months ago
It looks like Red Hat has fixes for the three listed above in RHEL, but they don't seem to be available in Fedora at least so we can't really get access to them. I would be willing to try the fix for CVE-2025-32049 on one of my systems though to see how it works.
The fix for CVE-2025-4035 is not in Epiphany-48.x, but is in 49.x. I'll make sure to mention that users should update to Epiphany-49.x to help guard against this vulnerability (but of course that's just one attack angle, it could get exploited in other applications as well)
We're also going to want to backport "soup-init: Use libdl instead of gmodule in soup2_is_loaded check" because it can cause deadlocks when libsoup is used with other libraries which also contend with GLib mutexes.
comment:16 by , 11 months ago
An additional CVE fix needs to be included - CVE-2025-12105. https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/481
CVE-2025-4035 is definitely best fixed via Epiphany. I'll update that ticket shortly to mention that it's security sensitive.
There is also https://gitlab.gnome.org/GNOME/libsoup/-/issues/446 - which hasn't been assigned a CVE, but was marked as a security report! I've included the patch from that which is https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/459
CVE-2025-9901 still doesn't appear to be resolved anywhere, and is still seen as relatively low priority. It's interesting though that Debian mentions that it could result in confidentiality problems in some environments.
https://gitlab.gnome.org/GNOME/libsoup/-/issues/469 has no fix but is noted that the impact is minimal to users (and no CVE was assigned)
https://gitlab.gnome.org/GNOME/libsoup/-/issues/471 has no fix but also has minimal impact, and relies on the attacker being able to view the system's logs.
https://gitlab.gnome.org/GNOME/libsoup/-/issues/468 is new but no fixes are available at this time, it looks like with the upstream backlog that there hasn't been time to look at this one
There are four additional issues open that we will not be able to view until December and January. https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home is where I'm getting that information
The fix for CVE-2025-32049 is one that requires an API change, which also bumps the package version to 3.7.0. One of the developers has noted that a downstream fix exists that doesn't include the API change, but it appears to only be available in Red Hat Enterprise Linux, and I haven't been able to find any other distributions that are carrying it. I have it on my system, but I don't feel comfortable adding it in unless another distro carries it, especially due to the need for an API change.
On that note, we still need https://gitlab.gnome.org/GNOME/libsoup/-/commit/2316e56a5502ac4c41ef4ff56a3266e680aca129 to fix a deadlock problem.
At the end of the day, this patch will fix:
- CVE-2025-12105: 7.5 High, remotely exploitable DoS (https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/481)
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/446 - a memory consumption problem that can lead to a remotely exploitable DoS
- CVE-2025-4948 (7.5 High, integer overflow leading to remotely exploitable denial of service): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/463
- CVE-2025-4945 (3.7 Low, integer overflow leading to undefined behavior. This allows attackers to bypass cookie expiration logic, causing persistent or unintended cookie behavior.): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/473
- CVE-2025-4969 (6.5 Medium, out-of-bounds read causing a crash or possibly information disclosure): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/467
- CVE-2025-4476 (4.3 Medium, denial-of-service when processing a malformed header): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/457
- CVE-2025-32914 (7.4 High, out-of-bounds read in soup_multipart_new_from_message()): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/450
- CVE-2025-32908 (7.5 High, HTTP/2 server doesn't properly validate some values of pseudo-headers :scheme:,:authority:, and :path: which causes a denial of service): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/451 and https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/453
- CVE-2025-32907 (5.3 Medium, resource consumption attack): Fixed by https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/452
- soup-init: Use libdl instead of gmodule in soup2_is_loaded check (https://gitlab.gnome.org/GNOME/libsoup/-/commit/2316e56a5502ac4c41ef4ff56a3266e680aca129)
comment:17 by , 11 months ago
| Summary: | Fix CVE-2025-32914, CVE-2025-32908 CVE-2025-32049, and CVE-2025-32907 in libsoup3 (Wait for issues to stabilize) → Fix CVE-2025-12105, CVE-2025-4948, CVE-2025-4945, CVE-2025-4969, CVE-2025-4476, CVE-2025-32914, CVE-2025-32908, and CVE-2025-32907 in libsoup3 |
|---|
comment:18 by , 11 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 21a21cbc02736ad9e974de308f1f2c91da7e0af6
SA-12.4-034 issued

It looks like there are more impending: