Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4514-1

Опубликовано: 23 дек. 2025
Источник: suse-cvrf

Описание

Security update for libsoup

This update for libsoup fixes the following issues:

  • CVE-2025-12105: Fixed heap use-after-free in message queue handling during HTTP/2 read completion (bsc#1252555)

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise Server 15 SP5-LTSS
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Manager Proxy LTS 4.3
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1
SUSE Manager Server LTS 4.3
libsoup-3_0-0-3.0.4-150400.3.21.1
libsoup-devel-3.0.4-150400.3.21.1
libsoup-lang-3.0.4-150400.3.21.1
typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1

Описание

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libsoup-3_0-0-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libsoup-devel-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libsoup-lang-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1

Ссылки

Описание

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libsoup-3_0-0-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libsoup-devel-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libsoup-lang-3.0.4-150400.3.21.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:typelib-1_0-Soup-3_0-3.0.4-150400.3.21.1

Ссылки