PT-2024-35361 · Gnome+11 · Gnome Libsoup+11

Published

2024-09-11

·

Updated

2025-09-05

·

CVE-2024-52532

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNOME libsoup versions prior to 3.6.1
Description The issue is related to an infinite loop and memory consumption during the reading of certain patterns of WebSocket data from clients.
Recommendations For versions prior to 3.6.1, update to version 3.6.1 or later to resolve the issue. As a temporary workaround, consider restricting the handling of WebSocket data from clients to minimize the risk of exploitation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

ALSA-2024:9559
ALSA-2024:9573
ALT-PU-2025-8157
ALT-PU-2025-8699
AZL-52998
AZL-53081
BDU:2025-05738
CESA-2024_9573
CVE-2024-52532
DLA-3992-1
INFSA-2024_9559
INFSA-2024_9573
MGASA-2024-0382
OESA-2024-2471
OESA-2024-2479
OPENSUSE-SU-2024:14488-1
OPENSUSE-SU-2024:14489-1
OPENSUSE-SU-2024_4290-1
OPENSUSE-SU-2024_4349-1
OPENSUSE-SU-2024_4352-1
OPENSUSE-SU-2024_4355-1
RHSA-2024:9559
RHSA-2024:9573
RHSA-2024_9559
RHSA-2024_9573
RLSA-2024:9559
RLSA-2024:9573
SUSE-SU-2024:4290-1
SUSE-SU-2024:4349-1
SUSE-SU-2024:4352-1
SUSE-SU-2024:4355-1
SUSE-SU-2024:4365-1
SUSE-SU-2025:1518-1
SUSE-SU-2025:20105-1
SUSE-SU-2025:20252-1
USN-7126-1
USN-7127-1
USN-7565-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Gnome Libsoup
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu