Back

LOW

Libsoup: integer overflow in cookie expiration date handling in libsoup

Published May 19, 2025

Description

A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.

Affected products

Remediation

Vendor solution

To mitigate the risk associated with this libsoup vulnerability, Red Hat recommends avoiding interactions between client applications using the libsoup library and untrusted or compromised HTTP servers until a patched version of libsoup is deployed. Users and administrators should monitor their systems for suspicious HTTP activity and apply vendor updates as soon as a fix becomes available to prevent manipulation of cookie expiration logic that could lead to unexpected behavior or policy circumvention.

Red Hat statement

The Red Hat Product Security team has assessed the severity of this vulnerability as Low. This assessment is based on the fact that successful exploitation requires an attacker to control or manipulate the expiration date of cookies sent from a malicious or compromised HTTP server. Additionally, the consequences of a successful attack are limited in scope affecting only the handling of cookie lifetimes within the local client instance, with no direct impact on system integrity, data confidentiality, or availability.

Red Hat mitigation

To mitigate the risk associated with this libsoup vulnerability, Red Hat recommends avoiding interactions between client applications using the libsoup library and untrusted or compromised HTTP servers until a patched version of libsoup is deployed. Users and administrators should monitor their systems for suspicious HTTP activity and apply vendor updates as soon as a fix becomes available to prevent manipulation of cookie expiration logic that could lead to unexpected behavior or policy circumvention.

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 19, 2025
Updated Jun 30, 2026
Reserved May 19, 2025
CISA Vulnrichment
Updated Mar 19, 2026
NVD
Status Deferred
Modified Jun 30, 2026
Red Hat
Severity Low
Public date May 19, 2025
ENISA EUVD
Assigner redhat
Published May 19, 2025
Updated Jun 30, 2026
Exploited since n/a
EUVD-2025-16034