Packages
- libsoup2.4 - HTTP client/server library for GNOME
- libsoup3 - HTTP client/server library for GNOME
Details
Jan Różański discovered that libsoup incorrectly handled certain headers
when sending HTTP/2 requests over TLS. An attacker could possibly use this
issue to cause a denial of service. This issue only affected libsoup3 in
Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-32908)
Jan Różański discovered that libsoup incorrectly parsed certain response
headers. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-4476)
Jan Różański discovered that libsoup incorrectly handled certain headers
when sending HTTP/2 requests over TLS. An attacker could possibly use this
issue to cause a denial of service. This issue only affected libsoup3 in
Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-32908)
Jan Różański discovered that libsoup incorrectly parsed certain response
headers. An attacker could possibly use this issue to cause a denial of
service. (CVE-2025-4476)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
25.04 plucky | libsoup-2.4-1 – 2.74.3-10ubuntu0.3 | ||
libsoup-3.0-0 – 3.6.5-1ubuntu0.1 | |||
24.10 oracular | libsoup-2.4-1 – 2.74.3-7ubuntu0.5 | ||
libsoup-3.0-0 – 3.6.0-2ubuntu0.4 | |||
24.04 noble | libsoup-2.4-1 – 2.74.3-6ubuntu1.5 | ||
libsoup-3.0-0 – 3.4.4-5ubuntu0.4 | |||
22.04 jammy | libsoup-3.0-0 – 3.0.7-0ubuntu1+esm4 | ||
libsoup2.4-1 – 2.74.2-3ubuntu0.5 | |||
20.04 focal | libsoup2.4-1 – 2.70.0-1ubuntu0.5 | ||
18.04 bionic | libsoup2.4-1 – 2.62.1-1ubuntu0.4+esm4 | ||
16.04 xenial | libsoup2.4-1 – 2.52.2-1ubuntu0.3+esm3 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.