PT-2024-10074 · Gnome+11 · Gnome Libsoup+11

Published

2024-08-27

·

Updated

2025-09-04

·

CVE-2024-52531

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNOME libsoup versions prior to 3.6.1
Description The issue is related to a buffer overflow in the soup header parse param list strict() function of the GNOME libsoup library. This overflow occurs in dynamic memory and is associated with applications that perform conversion to UTF-8. Although initial reports suggested that input received over the network could not trigger this issue, further analysis indicates that it might be possible. The exploitation of this issue could allow an attacker to cause a denial of service.
Recommendations For versions prior to 3.6.1, update to version 3.6.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the soup header parse param list strict() function until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:0791
ALSA-2025:0838
ALT-PU-2025-8157
ALT-PU-2025-8699
AZL-53063
AZL-53076
BDU:2025-00232
CESA-2025_0838
CVE-2024-52531
DLA-3992-1
INFSA-2025_0791
INFSA-2025_0838
MGASA-2024-0382
OESA-2024-2471
OESA-2024-2601
OPENSUSE-SU-2024:14488-1
OPENSUSE-SU-2024:14489-1
OPENSUSE-SU-2024_4290-1
OPENSUSE-SU-2024_4349-1
OPENSUSE-SU-2024_4352-1
OPENSUSE-SU-2024_4355-1
RHSA-2025:0791
RHSA-2025:0838
RHSA-2025:0847
RHSA-2025:0848
RHSA-2025:0882
RHSA-2025:0889
RHSA-2025:0903
RHSA-2025:0949
RHSA-2025:1047
RHSA-2025:1075
RHSA-2025_0791
RHSA-2025_0838
RLSA-2025:0791
RLSA-2025:0838
ROSA-SA-2025-2758
SUSE-SU-2024:4290-1
SUSE-SU-2024:4349-1
SUSE-SU-2024:4352-1
SUSE-SU-2024:4355-1
SUSE-SU-2024:4365-1
SUSE-SU-2025:1518-1
SUSE-SU-2025:20105-1
SUSE-SU-2025:20252-1
USN-7126-1
USN-7127-1
USN-7565-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Gnome Libsoup
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu