Junglewise Threat Intelligence

CVE-2025-11021: GNOME libsoup out-of-bounds read in cookie date handling

CVE-2025-11021 · Severity: high · CVSS 7.5 · Published 2025-09-26

Technologies: Red Hat Enterprise Linux 10, Gnome Libsoup, Red Hat Enterprise Linux 9. Vendors: Red Hat, Gnome.

Executive brief

A security vulnerability has been identified in libsoup, a widely used software library that allows applications to communicate over the internet. The flaw occurs when the library processes web cookies with specifically manipulated expiration dates. If exploited, this could allow an attacker to view sensitive information stored in the memory of the affected application, potentially leading to the exposure of private data or credentials.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the cookie date handling logic of the libsoup HTTP library. The issue is triggered when the library parses a 'Set-Cookie' header containing a specially crafted expiration date string. A remote, unauthenticated attacker can exploit this by sending a malicious HTTP response to an application using libsoup. Successful exploitation allows the attacker to read sensitive information from the process's memory space. Patches have been released by GNOME and various Linux distributions including Red Hat.

Affected products

  • GNOME libsoup <= 3.6.5
  • Red Hat Red Hat Enterprise Linux 10 libsoup3 < 3.6.5-3.el10_0.7
  • Red Hat Red Hat Enterprise Linux 9 libsoup < 2.72.0-10.el9_6.3

Timeline

  • 2025-09-26: advisory: Initial CVE publication
  • 2025-10-15: patched: Red Hat released security updates for RHEL 10

References

Related threats