Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2025-32911: libsoup2.4 can let malicious web client corrupt memory
CVE-2025-32911 · published 1 year ago
Summary
The libsoup2.4 library used in Debian systems can be tricked by a crafted web request to overwrite its own memory, which could cause the program to crash or behave unpredictably. This affects the standard libsoup2.4 package and the rootio‑libsoup2.4 variant. Apply the latest security updates for these packages to protect your servers.
What to do
- Update debian libsoup2.4 to version 2.74.3-1+deb12u1.aikido.3.
- Update debian rootio-libsoup2.4 to version 2.74.3-1+deb12u1.aikido.3.
- Update debian libsoup2.4 to version 2.74.3-1+deb12u1.aikido.1.
- Update debian rootio-libsoup2.4 to version 2.74.3-1+deb12u1.aikido.1.
- Update libsoup2.4 to version 2.74.3-1+deb12u1.aikido.5.
- Update rootio-libsoup2.4 to version 2.74.3-1+deb12u1.aikido.5.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:12 | debian | libsoup2.4 |
< 2.74.3-1+deb12u1.aikido.3 < 2.74.3-1+deb12u1.aikido.1 Fix: upgrade to 2.74.3-1+deb12u1.aikido.3
|
| Root:Debian:12 | debian | rootio-libsoup2.4 |
< 2.74.3-1+deb12u1.aikido.3 < 2.74.3-1+deb12u1.aikido.1 Fix: upgrade to 2.74.3-1+deb12u1.aikido.3
|
| Root:Debian:12 | – | libsoup2.4 |
< 2.74.3-1+deb12u1.aikido.5 Fix: upgrade to 2.74.3-1+deb12u1.aikido.5
|
| Root:Debian:12 | – | rootio-libsoup2.4 |
< 2.74.3-1+deb12u1.aikido.5 Fix: upgrade to 2.74.3-1+deb12u1.aikido.5
|
Original advisory text
CVE-2025-32911 in libsoup2.4 - Patched by Root
A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.
References
- https://access.redhat.com/errata/RHSA-2025:21657
- https://access.redhat.com/errata/RHSA-2025:4439
- https://access.redhat.com/errata/RHSA-2025:4440
- https://access.redhat.com/errata/RHSA-2025:4508
- https://access.redhat.com/errata/RHSA-2025:4538
- https://access.redhat.com/errata/RHSA-2025:4560
- https://access.redhat.com/errata/RHSA-2025:4568
- https://access.redhat.com/errata/RHSA-2025:4609
- https://access.redhat.com/errata/RHSA-2025:4624
- https://access.redhat.com/errata/RHSA-2025:7436
- https://access.redhat.com/errata/RHSA-2025:8292
- https://access.redhat.com/errata/RHSA-2025:9179
- https://access.redhat.com/security/cve/CVE-2025-32911
- https://bugzilla.redhat.com/show_bug.cgi?id=2359355
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/433
- https://lists.debian.org/debian-lts-announce/2025/04/msg00036.html
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-590Free of Memory not on the Heap
Timeline
Published15 Apr 2025
Updated7 Oct 2026
First seen7 Mar 2026
Track software like this
Free during beta