Логотип exploitDog
bind:CVE-2025-12105
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-12105

Количество 9

Количество 9

ubuntu логотип

CVE-2025-12105

4 месяца назад

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-12105

4 месяца назад

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-12105

около 2 месяцев назад

Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-12105

4 месяца назад

A flaw was found in the asynchronous message queue handling of the lib ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0017-1

около 1 месяца назад

Security update for libsoup

EPSS: Низкий
rocky логотип

RLSA-2025:23139

около 2 месяцев назад

Moderate: libsoup3 security update

EPSS: Низкий
github логотип

GHSA-gppq-jw9r-4v4j

4 месяца назад

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-23139

2 месяца назад

ELSA-2025-23139: libsoup3 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4514-1

около 2 месяцев назад

Security update for libsoup

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-12105

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-12105

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

CVSS3: 7.5
0%
Низкий
4 месяца назад
msrc логотип
CVE-2025-12105

Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-12105

A flaw was found in the asynchronous message queue handling of the lib ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0017-1

Security update for libsoup

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2025:23139

Moderate: libsoup3 security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-gppq-jw9r-4v4j

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.

CVSS3: 7.5
0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2025-23139

ELSA-2025-23139: libsoup3 security update (MODERATE)

2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4514-1

Security update for libsoup

около 2 месяцев назад

Уязвимостей на страницу