Description
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service.
Problem types
Excessive Platform Resource Consumption within a Loop
Product status
Any version before 3.6.5
0:3.6.5-3.el10_0.6 (rpm) before *
0:2.8-3.el8_10.1 (rpm) before *
0:8.10-1 (rpm) before *
0:2.72.0-10.el9_6.1 (rpm) before *
0:2.72.0-8.el9_0.4 (rpm) before *
0:2.72.0-8.el9_2.4 (rpm) before *
0:2.72.0-8.el9_4.4 (rpm) before *
Timeline
| 2025-04-14: | Reported to Red Hat. |
| 2025-04-14: | Made public. |
References
access.redhat.com/errata/RHSA-2025:4439 (RHSA-2025:4439)
access.redhat.com/errata/RHSA-2025:4440 (RHSA-2025:4440)
access.redhat.com/errata/RHSA-2025:4508 (RHSA-2025:4508)
access.redhat.com/errata/RHSA-2025:7436 (RHSA-2025:7436)
access.redhat.com/errata/RHSA-2025:8128 (RHSA-2025:8128)
access.redhat.com/errata/RHSA-2025:8292 (RHSA-2025:8292)
access.redhat.com/security/cve/CVE-2025-32907
bugzilla.redhat.com/show_bug.cgi?id=2359342 (RHBZ#2359342)