Resource exhaustion in libsoup - CVE-2025-32049
Published: May 29, 2025
Vulnerability identifier: #VU109940
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32049
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in SoupWebsocketConnection. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
libsoup
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libsoup (Red Hat package)
libsoup-devel
libsoup
libsoup-doc
libsoup-debuginfo
libsoup-debugsource
libsoup-help
mingw-libsoup
libsoup3 (Red Hat package)
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libsoup (Red Hat package)
libsoup-devel
libsoup
libsoup-doc
libsoup-debuginfo
libsoup-debugsource
libsoup-help
mingw-libsoup
libsoup3 (Red Hat package)
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
How to mitigate CVE-2025-32049
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
libsoup (Red Hat package) - addressed in versions 2.62.2-6.el7_9, 2.62.2-9.el7_9, 2.62.3-1.el8_2.5, 2.62.3-2.el8_4.5, 2.62.3-2.el8_6.5, 2.62.3-3.el8_8.5, 2.62.3-9.el8_10, 2.72.0-8.el9_0.5, 2.72.0-8.el9_2.5, 2.72.0-8.el9_4.5, 2.72.0-10.el9_6.2
libsoup-devel - addressed in versions 2.62.2-7, 2.62.2-9, 2.62.3-9.0.1
libsoup - addressed in versions 2.62.2-7, 2.62.2-9, 2.62.3-9.0.1
libsoup-doc - update to 2.62.3-9.0.1
libsoup - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-debuginfo - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-debugsource - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-devel - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-help - addressed in versions 2.71.0-18, 2.74.2-19
mingw-libsoup - addressed in versions 2.74.3-12.fc41, 2.74.3-12.fc42
libsoup3 (Red Hat package) - update to 3.6.5-3.el10_0.6
Red Hat OpenShift Container Platform - addressed in versions 4.17.32, 4.18.16
IBM Cloud Pak for Multicloud Management - update to 2.3 Fix Pack 12
libsoup (Red Hat package) - addressed in versions 2.62.2-6.el7_9, 2.62.2-9.el7_9, 2.62.3-1.el8_2.5, 2.62.3-2.el8_4.5, 2.62.3-2.el8_6.5, 2.62.3-3.el8_8.5, 2.62.3-9.el8_10, 2.72.0-8.el9_0.5, 2.72.0-8.el9_2.5, 2.72.0-8.el9_4.5, 2.72.0-10.el9_6.2
libsoup-devel - addressed in versions 2.62.2-7, 2.62.2-9, 2.62.3-9.0.1
libsoup - addressed in versions 2.62.2-7, 2.62.2-9, 2.62.3-9.0.1
libsoup-doc - update to 2.62.3-9.0.1
libsoup - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-debuginfo - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-debugsource - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-devel - addressed in versions 2.71.0-18, 2.74.2-19
libsoup-help - addressed in versions 2.71.0-18, 2.74.2-19
mingw-libsoup - addressed in versions 2.74.3-12.fc41, 2.74.3-12.fc42
libsoup3 (Red Hat package) - update to 3.6.5-3.el10_0.6
Red Hat OpenShift Container Platform - addressed in versions 4.17.32, 4.18.16
External References
Related Security Bulletins
- Multiple vulnerabilities in libsoup
- Red Hat Enterprise Linux 9 update for libsoup
- Red Hat Enterprise Linux 10 update for libsoup3
- Red Hat Enterprise Linux 8 update for libsoup
- Red Hat Enterprise Linux 9 update for libsoup
- Red Hat Enterprise Linux 9 update for libsoup
- Red Hat Enterprise Linux 8 update for libsoup
- Fedora 42 update for mingw-libsoup
- Fedora 41 update for mingw-libsoup
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Red Hat Enterprise Linux 8 update for libsoup
- Red Hat Enterprise Linux 9 update for libsoup
- Red Hat Enterprise Linux 8 update for libsoup
- Anolis OS update for libsoup
- Red Hat Enterprise Linux 8 update for libsoup
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for libsoup
- Anolis OS update for libsoup
- Multiple vulnerabilities in IBM Power Hardware Management Console (HMC)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Total Storage Service Console (TSSC) / TS4500 IMC
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for libsoup
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Anolis OS update for libsoup
- openEuler 22.03 LTS SP4 update for libsoup
- openEuler 20.03 LTS SP4 update for libsoup