CVE-2025-2784

Updated: 2025-06-24 01:13:53.278175

Description:

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU libsoup 2.72.0 6.5 MEDIUM Released CLSA-2025:1749569869 2025-06-11 00:54:46
AlmaLinux 9.2 ESU kernel 5.14.0 6.5 MEDIUM Ignored 2025-06-10 00:24:22
AlmaLinux 9.6 ESU kernel 5.14.0 6.5 MEDIUM Ignored 2025-07-05 05:53:05
CentOS 7 ELS libsoup 2.62.2 6.5 MEDIUM In Testing 2025-07-05 02:18:59
CentOS 8.4 ELS kernel 4.18.0 6.5 MEDIUM Ignored 2025-06-10 00:24:23
CentOS 8.5 ELS kernel 4.18.0 6.5 MEDIUM Ignored 2025-06-10 00:24:23
CentOS Stream 8 ELS kernel 4.18.0 6.5 MEDIUM Ignored 2025-06-10 00:24:22
Oracle Linux 7 ELS libsoup 2.62.2 6.5 MEDIUM In Testing 2025-07-05 02:18:58
RHEL 7 ELS libsoup 2.62.2 6.5 MEDIUM In Testing 2025-07-05 02:18:59
Ubuntu 16.04 ELS linux-hwe 4.15.0 6.5 MEDIUM Ignored 2025-06-14 00:37:31
Total: 12