<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2025-0194</id>
    <title>An update for libsoup is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2025-06-25 17:09:25"/>
    <updated date="2025-06-25 17:09:25"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-46420" id="CVE-2025-46420" title="CVE-2025-46420 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-4969" id="CVE-2025-4969" title="CVE-2025-4969 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-32909" id="CVE-2025-32909" title="CVE-2025-32909 Base Score: 5.3 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-46421" id="CVE-2025-46421" title="CVE-2025-46421 Base Score: 6.8 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-32050" id="CVE-2025-32050" title="CVE-2025-32050 Base Score: 5.9 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-4948" id="CVE-2025-4948" title="CVE-2025-4948 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes. (CVE-2025-46420)

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read). (CVE-2025-4969)

A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash. (CVE-2025-32909)

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the original host that issued the redirect. (CVE-2025-46421)

A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read. (CVE-2025-32050)

A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can go wrong, leading to an integer underflow. This can cause the program to access invalid memory and crash. As a result, any application or server using libsoup could be forced to exit unexpectedly, creating a denial-of-service (DoS) risk. (CVE-2025-4948)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="libsoup">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="libsoup" version="2.74.2" release="1.r8.hce2">
          <filename>libsoup-2.74.2-1.r8.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libsoup-devel" version="2.74.2" release="1.r8.hce2">
          <filename>libsoup-devel-2.74.2-1.r8.hce2.aarch64.rpm</filename>
        </package>
        <package arch="noarch" name="libsoup-help" version="2.74.2" release="1.r8.hce2">
          <filename>libsoup-help-2.74.2-1.r8.hce2.noarch.rpm</filename>
        </package>
        <package arch="x86_64" name="libsoup" version="2.74.2" release="1.r8.hce2">
          <filename>libsoup-2.74.2-1.r8.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libsoup-devel" version="2.74.2" release="1.r8.hce2">
          <filename>libsoup-devel-2.74.2-1.r8.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
