Resource exhaustion in libsoup - CVE-2025-32049

 

Resource exhaustion in libsoup - CVE-2025-32049

Published: May 29, 2025


Vulnerability identifier: #VU109940
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32049
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in SoupWebsocketConnection. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

libsoup
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libsoup (Red Hat package)
libsoup-devel
libsoup
libsoup-doc
libsoup-debuginfo
libsoup-debugsource
libsoup-help
mingw-libsoup
libsoup3 (Red Hat package)
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform

How to mitigate CVE-2025-32049

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
libsoup (Red Hat package) - addressed in versions 2.62.2-6.el7_9, 2.62.2-9.el7_9, 2.62.3-1.el8_2.5, 2.62.3-2.el8_4.5, 2.62.3-2.el8_6.5, 2.62.3-3.el8_8.5, 2.62.3-9.el8_10, 2.72.0-8.el9_0.5, 2.72.0-8.el9_2.5, 2.72.0-8.el9_4.5, 2.72.0-10.el9_6.2
libsoup-devel - addressed in versions 2.62.2-7, 2.62.2-9, 2.62.3-9.0.1
libsoup - addressed in versions 2.62.2-7, 2.62.2-9, 2.62.3-9.0.1
libsoup-doc - update to 2.62.3-9.0.1
libsoup - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-debuginfo - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-debugsource - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-devel - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-help - addressed in versions 2.71.0-18, 2.74.2-19
mingw-libsoup - addressed in versions 2.74.3-12.fc41, 2.74.3-12.fc42
libsoup3 (Red Hat package) - update to 3.6.5-3.el10_0.6
Red Hat OpenShift Container Platform - addressed in versions 4.17.32, 4.18.16

External References

Related Security Bulletins