|
|
Log in / Subscribe / Register

Ubuntu alert USN-7565-1 (libsoup2.4)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7565-1] libsoup vulnerabilities
Date:  Wed, 11 Jun 2025 23:26:52 +0000
Message-ID:  <E1uPUqK-0001An-V5@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7565-1 June 11, 2025 libsoup2.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in libsoup. Software Description: - libsoup2.4: HTTP client/server library for GNOME Details: It was discovered that libsoup did not correctly handle memory while performing UTF-8 conversions. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2024-52531) It was discovered that libsoup could enter an infinite loop when reading certain websocket data. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2024-52532) It was discovered that libsoup could be made to read out of bounds. An attacker could possibly use this issue to cause applications using libsoup to crash, resulting in a denial of service. (CVE-2025-2784, CVE-2025-32050, CVE-2025-32052, CVE-2025-32053) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libsoup2.4-1 2.62.1-1ubuntu0.4+esm5 Available with Ubuntu Pro Ubuntu 16.04 LTS libsoup2.4-1 2.52.2-1ubuntu0.3+esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7565-1 CVE-2024-52531, CVE-2024-52532, CVE-2025-2784, CVE-2025-32050, CVE-2025-32052, CVE-2025-32053


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmhKEDoACgkQcpJm3tlz hgHoxg/+JfAZJToawG/1zFLTeAMuYwMDrlcBgoAA8ukKHYpPgUlAZTZrfqDnP4ME fI/jqdw+gXBzRjPxrHphtBfOHCHT2PF55zt9NMqllA0R4LdWXfCJyDfFKTj76IK9 5xqk+IRpitA5NFzEfONyeEjj3lnTr2Q+CJFhDUO7ZzujPyxkod16BsTtdleFh+DA HMn4D+lPyd8GjGh6ZkDZqB7Fsema4XPjYDZG/jc6KgvzbJy3XaaylxUqI9V6cQ4v 2ExdneJnrhoZ83rhDfDekvjVISV5AhfA4d90df++B5YSWykzs2Jun+FXmhaUbOao kciyZzvjM/LvqQfI0cD9JGAg4IS/iUExDlXbxCYDBgxyuNinokiA06YWtuF7ofCL 8RqW+Yq+e0cKKsajCAG9M+5oP5XpzMh+2irZ7wtLO2WS9D2/zDenQCMIPilPG/H6 vB+TnIYYHeX99Ak2h9ixlwWWCnR3WiYIki3Ps3FZLSYJEUdEuiTghlKX9U5TTFgZ 4RDNxn/hJM1ejuKvyycLD2Id8BxtmxLCps8LA6UcPkqFPNEZ1DYgILmcctHfOsAk XiiuimNUYYPC68qNRETk1UI9W4QR4KueP1OPbzkV5nfDgRSBAaxP5pcF4xlF8K9Y UgxlGQUokS2MLnqOdbXtOdFdF1ESpDepSvm/oV3DioyGC2uxP3w= =NUeN -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds