USN-7432-1: libsoup vulnerabilities
10 April 2025
Several security issues were fixed in libsoup.
Releases
Packages
- libsoup2.4 - HTTP client/server library for GNOME
- libsoup3 - GObject introspection data for the libsoup HTTP library
Details
It was discovered that libsoup could be made to read out of bounds. An
attacker could possibly use this issue to cause applications using
libsoup to crash, resulting in a denial of service. (CVE-2025-2784,
CVE-2025-32050, CVE-2025-32052, CVE-2025-32053)
It was discovered that libsoup could be made to dereference invalid
memory. An attacker could possibly use this issue to cause applications
using libsoup to crash, resulting in a denial of service.
(CVE-2025-32051)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
Ubuntu 24.04
Ubuntu 22.04
-
libsoup-3.0-0
-
3.0.7-0ubuntu1+esm2
Available with Ubuntu Pro
-
libsoup2.4-1
-
2.74.2-3ubuntu0.2
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.