﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21576	Fix CVE-2025-12105, CVE-2025-4948, CVE-2025-4945, CVE-2025-4969, CVE-2025-4476, CVE-2025-32914, CVE-2025-32908, and CVE-2025-32907 in libsoup3	Douglas R. Reno	Douglas R. Reno	"Four new security vulnerabilities have been found in libsoup3 that we should patch, alongside those in libsoup2.

Patches can be found at https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/451, https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/453, https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/450, https://gitlab.gnome.org/GNOME/libsoup/-/commit/c4c4eedbb71cba15075ac55a171aeac27e7bfd45 (for CVE-2025-32049), and https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/452

While these are only denial of service vulnerabilities, they can both be exploited remotely. When I file the security advisory for this, I'll also need to factor in bugs that were later assigned CVEs fixed in 3.6.5.

Thank you again to Joe Locash for the pointers on this, and to upstream for making more information available so we can act on it.

- CVE-2025-32914: 7.4 High, remotely exploitable out of bounds read
- CVE-2025-32908: 7.4 High, remotely exploitable crash
- CVE-2025-32049: 7.5 High, remotely exploitable crash
- CVE-2025-32907: 5.3 Medium, excessive memory consumption

The security vulnerabilities fixed in previous versions that we need to document are:

- CVE-2025-32050 - Integer overflow in append_param_quoted
  Date Fixed: November 22, 2024

- CVE-2025-32051 - Segmentation fault when parsing malformed data URI
  Date Fixed: November 22, 2024

- CVE-2025-32052 - Heap buffer over-read in soup-content-sniffer.c:sniff_unknown()
  Date Fixed: November 22, 2024

- CVE-2025-32053 - Heap buffer over-read in soup-content-sniffer.c:sniff_feed_or_html() and soup-content-sniffer.c:skip_insignificant_space()
  Date Fixed: November 22, 2024

- CVE-2025-32906 - Out of bounds reads in soup_headers_parse_request()
  Date Fixed: February 24, 2025

- CVE-2025-32909 - NULL Pointer Dereference on libsoup through function ""sniff_mp4"" in soup-content-sniffer.c
  Date Fixed: January 8, 2025

- CVE-2025-32910 - Null pointer deference on libsoup via /auth/soup-auth-digest.c through ""soup_auth_digest_authenticate"" on client when server omits the ""realm"" parameter in an Unauthorized response with Digest authentication
  Date Fixed: January 10, 2025

- CVE-2025-32911 - Double free on soup_message_headers_get_content_disposition() through ""soup-message-headers.c"" via ""params"" GHashTable value
  Date Fixed: January 8, 2025

- CVE-2025-32912 - NULL pointer dereference in client when server omits the ""nonce"" parameter in an Unauthorized response with Digest authentication
  Date Fixed: February 8, 2025

- CVE-2025-32913 - NULL pointer dereference in soup_message_headers_get_content_disposition when ""filename"" parameter is present, but has no value in Content-Disposition header
  Date Fixed: January 8, 2025"	enhancement	closed	high	13.0	BOOK	git	medium	fixed		
