Executive brief
A security vulnerability has been identified in libsoup, a networking library used by many Linux applications to handle web communications. An attacker can remotely trigger a memory error that causes applications using this library to crash. This could lead to a denial-of-service, disrupting business operations and application availability.
Technical details
A use-after-free (UAF) vulnerability exists in libsoup's asynchronous message queue handling during HTTP/2 read completion. The flaw is caused by missing state synchronization when network operations are aborted at specific timing intervals, allowing an internal message queue item to be freed twice. A remote, unauthenticated attacker can exploit this by sending specific HTTP/2 read and cancel sequences to an application using the library. Successful exploitation results in memory corruption and a denial-of-service (DoS) condition. Patches have been released by GNOME and Red Hat to address the synchronization logic.
Affected products
- GNOME libsoup <= 3.6.5
- Red Hat Red Hat Enterprise Linux 10.0 EUS libsoup3 < 3.6.5-3.el10_0.10
- Red Hat Red Hat Enterprise Linux 10.1 libsoup3 < 3.6.5-3.el10_1.7
Timeline
- 2025-10-23: disclosed
- 2025-12-11: patched: Red Hat released updates for RHEL 10.1
- 2025-12-17: patched: Red Hat released updates for RHEL 10.0 EUS
References
- https://gitlab.gnome.org/GNOME/libsoup
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/errata/RHSA-2025:23139
- https://access.redhat.com/errata/RHSA-2025:23437
- https://access.redhat.com/security/cve/CVE-2025-12105
- https://bugzilla.redhat.com/show_bug.cgi?id=2405992
- https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/481