← Back to CVE List
Vulnerability Intelligence Report
Libsoup: double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" ghashtable value

CVE-2025-32911

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

No Active Exploit Signals
CVSS Base Score
9.0
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:0.80%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-590 ↗Free of Memory not on the Heap

Affected Products & Versions

Vendor Product Affected Versions
0 < 3.6.3 (affected)
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.62.2-9.el7_9 < * (unaffected)
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.62.2-6.el7_9 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 0:2.62.3-8.el8_10 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 0:2.8-3.el8_10.1 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 0:8.10-1 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8 0:2.62.3-8.el8_10 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support 0:2.62.3-1.el8_2.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.62.3-2.el8_4.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Telecommunications Update Service 0:2.62.3-2.el8_4.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions 0:2.62.3-2.el8_4.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.62.3-2.el8_6.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service 0:2.62.3-2.el8_6.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions 0:2.62.3-2.el8_6.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 8.8 Extended Update Support 0:2.62.3-3.el8_8.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9 0:2.72.0-10.el9_6.1 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions 0:2.72.0-8.el9_0.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support 0:2.72.0-8.el9_2.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support 0:2.72.0-8.el9_4.4 < * (unaffected)
Red Hat Red Hat Enterprise Linux 10 all
Red Hat Red Hat Enterprise Linux 6 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.798%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2025-04-14T01:59:13
Published2025-04-15T15:39:34
Patch Date2025-04-14
Last Updated2026-06-29T21:26:53

LINK COPIED TO CLIPBOARD