CVE-2025-4948

EUVD-2025-15741
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk.
Wrap or Wraparound
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Debian logo
Debian Releases
Debian Product
Codename
libsoup2.4
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
2.72.0-2+deb11u3
fixed
trixie
no-dsa
libsoup3
bookworm
no-dsa
forky
3.6.6-1
fixed
sid
3.6.6-1
fixed
trixie
3.6.5-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libsoup3
focal
dne
jammy
Fixed 3.0.7-0ubuntu1+esm5
released
noble
Fixed 3.4.4-5ubuntu0.5
released
oracular
ignored
plucky
Fixed 3.6.5-1ubuntu0.2
released
questing
Fixed 3.6.5-3
released
resolute
Fixed 3.6.5-3
released
libsoup2.4
bionic
Fixed 2.62.1-1ubuntu0.4+esm6
released
focal
Fixed 2.70.0-1ubuntu0.5+esm1
released
jammy
Fixed 2.74.2-3ubuntu0.6
released
noble
Fixed 2.74.3-6ubuntu1.6
released
oracular
ignored
plucky
Fixed 2.74.3-10ubuntu0.4
released
questing
Fixed 2.74.3-10.1ubuntu4
released
resolute
Fixed 2.74.3-10.1ubuntu4
released
xenial
Fixed 2.52.2-1ubuntu0.3+esm5
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libsoup-2_4-1
suse enterprise desktop 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise desktop 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise server 12 SP3
2.62.2-5.15.1
fixed
suse enterprise server 12 SP5
2.62.2-5.15.1
fixed
suse enterprise server 15 SP2
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP3
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise server 15 SP7
2.74.3-150600.4.9.1
fixed
libsoup-2_4-1-32bit
suse enterprise server 12 SP3
2.62.2-5.15.1
fixed
suse enterprise server 12 SP5
2.62.2-5.15.1
fixed
libsoup-3_0-0
suse enterprise desktop 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise desktop 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise server 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise server 15 SP7
3.4.4-150600.3.10.1
fixed
libsoup-devel
suse enterprise desktop 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise desktop 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise server 12 SP3
2.62.2-5.15.1
fixed
suse enterprise server 12 SP5
2.62.2-5.15.1
fixed
suse enterprise server 15 SP2
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP3
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise server 15 SP7
3.4.4-150600.3.10.1
fixed
libsoup-lang
suse enterprise desktop 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise desktop 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise server 12 SP3
2.62.2-5.15.1
fixed
suse enterprise server 12 SP5
2.62.2-5.15.1
fixed
suse enterprise server 15 SP2
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP3
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise server 15 SP7
3.4.4-150600.3.10.1
fixed
libsoup2-devel
suse enterprise desktop 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise desktop 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise server 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise server 15 SP7
2.74.3-150600.4.9.1
fixed
libsoup2-lang
suse enterprise desktop 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise desktop 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise server 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise server 15 SP7
2.74.3-150600.4.9.1
fixed
typelib-1_0-Soup-2_4
suse enterprise desktop 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise desktop 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise sap 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise sap 15 SP7
2.74.3-150600.4.9.1
fixed
suse enterprise server 12 SP3
2.62.2-5.15.1
fixed
suse enterprise server 12 SP5
2.62.2-5.15.1
fixed
suse enterprise server 15 SP2
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP3
2.68.4-150200.4.9.1
fixed
suse enterprise server 15 SP4
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP5
2.74.2-150400.3.9.1
fixed
suse enterprise server 15 SP6
2.74.3-150600.4.9.1
fixed
suse enterprise server 15 SP7
2.74.3-150600.4.9.1
fixed
typelib-1_0-Soup-3_0
suse enterprise desktop 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise desktop 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise sap 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise sap 15 SP7
3.4.4-150600.3.10.1
fixed
suse enterprise server 15 SP4
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP5
3.0.4-150400.3.10.1
fixed
suse enterprise server 15 SP6
3.4.4-150600.3.10.1
fixed
suse enterprise server 15 SP7
3.4.4-150600.3.10.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
libsoup
RHEL 8
0:2.62.3-9.el8_10
fixed
RHEL 8.2 AUS
0:2.62.3-1.el8_2.5
fixed
RHEL 8.4 AUS
0:2.62.3-2.el8_4.5
fixed
RHEL 8.6 AUS
0:2.62.3-2.el8_6.5
fixed
RHEL 8.6 E4S
0:2.62.3-2.el8_6.5
fixed
RHEL 8.6 TUS
0:2.62.3-2.el8_6.5
fixed
RHEL 8.8 AUS
0:2.62.3-3.el8_8.5
fixed
RHEL 8.8 E4S
0:2.62.3-3.el8_8.5
fixed
RHEL 8.8 EUS
0:2.62.3-3.el8_8.5
fixed
RHEL 8.8 TUS
0:2.62.3-3.el8_8.5
fixed
RHEL 9
0:2.72.0-10.el9_6.2
fixed
libsoup-devel
RHEL 8
0:2.62.3-9.el8_10
fixed
RHEL 8.2 AUS
0:2.62.3-1.el8_2.5
fixed
RHEL 8.4 AUS
0:2.62.3-2.el8_4.5
fixed
RHEL 8.6 AUS
0:2.62.3-2.el8_6.5
fixed
RHEL 8.6 E4S
0:2.62.3-2.el8_6.5
fixed
RHEL 8.6 TUS
0:2.62.3-2.el8_6.5
fixed
RHEL 8.8 AUS
0:2.62.3-3.el8_8.5
fixed
RHEL 8.8 E4S
0:2.62.3-3.el8_8.5
fixed
RHEL 8.8 EUS
0:2.62.3-3.el8_8.5
fixed
RHEL 8.8 TUS
0:2.62.3-3.el8_8.5
fixed
RHEL 9
0:2.72.0-10.el9_6.2
fixed