PT-2025-22321 · Libsoup+5 · Libsoup+5

Published

2025-01-01

·

Updated

2026-05-15

·

CVE-2025-4969

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions libsoup versions 2.4 through 3
Description A flaw was found in the libsoup package due to its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries, resulting in an out-of-bounds read.
Recommendations For versions 2.4 through 3, consider restricting access to the multipart HTTP message handling functionality until a patch is available. As a temporary workaround, disabling the vulnerable function related to multipart HTTP message verification may help minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-61945
AZL-61958
BDU:2025-10261
CVE-2025-4969
DLA-4398-1
OESA-2025-1632
OESA-2026-2337
OESA-2026-2338
OESA-2026-2339
OPENSUSE-SU-2025:15185-1
OPENSUSE-SU-2025:15189-1
SUSE-SU-2025:01794-1
SUSE-SU-2025:01801-1
SUSE-SU-2025:01802-1
SUSE-SU-2025:01812-1
SUSE-SU-2025:01817-1
SUSE-SU-2025:01864-1
SUSE-SU-2025:20453-1
SUSE-SU-2025:20598-1
SUSE-SU-2025_01794-1
SUSE-SU-2025_01812-1
SUSE-SU-2025_01817-1
USN-7643-1

Affected Products

Debian
Linuxmint
Red Os
Suse
Ubuntu
Libsoup