Libsoup: integer overflow in cookie expiration date handling in libsoup
Published May 19, 2025
3.7
LOWCVSS 3.1
EPSS 0.67%
Description
A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 10
libsoup3-0:3.6.5-3.el10_0.9
Fixed · RHSA-2025:19720
Red Hat Enterprise Linux 10
libsoup3-0:3.6.5-3.el10_1.6
Fixed · RHSA-2025:21032
Red Hat Enterprise Linux 7 Extended Lifecycle Support
libsoup-0:2.62.2-9.el7_9
Fixed · RHSA-2025:21657
Red Hat Enterprise Linux 8
libsoup-0:2.62.3-10.el8_10
Fixed · RHSA-2025:19714
Red Hat Enterprise Linux 8
libsoup-0:2.62.3-10.el8_10
Fixed · RHSA-2025:19714
Red Hat Enterprise Linux 8.2 Advanced Update Support
libsoup-0:2.62.3-1.el8_2.6
Fixed · RHSA-2025:22013
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libsoup-0:2.62.3-2.el8_4.6
Fixed · RHSA-2025:21772
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
libsoup-0:2.62.3-2.el8_4.6
Fixed · RHSA-2025:21772
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
libsoup-0:2.62.3-2.el8_6.6
Fixed · RHSA-2025:21664
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
libsoup-0:2.62.3-2.el8_6.6
Fixed · RHSA-2025:21664
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
libsoup-0:2.62.3-2.el8_6.6
Fixed · RHSA-2025:21664
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
libsoup-0:2.62.3-3.el8_8.6
Fixed · RHSA-2025:21665
Red Hat Enterprise Linux 9
libsoup-0:2.72.0-10.el9_6.3
Fixed · RHSA-2025:19713
Red Hat Enterprise Linux 9
libsoup-0:2.72.0-12.el9_7.1
Fixed · RHSA-2025:20959
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
libsoup-0:2.72.0-8.el9_0.6
Fixed · RHSA-2025:21656
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
libsoup-0:2.72.0-8.el9_2.6
Fixed · RHSA-2025:21655
Red Hat Enterprise Linux 9.4 Extended Update Support
libsoup-0:2.72.0-8.el9_4.6
Fixed · RHSA-2025:21666
Red Hat Enterprise Linux 6
libsoup
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libsoup3-0:3.6.5-3.el10_0.9 | Fixed | RHSA-2025:19720 |
| Red Hat Enterprise Linux 10 | libsoup3-0:3.6.5-3.el10_1.6 | Fixed | RHSA-2025:21032 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | libsoup-0:2.62.2-9.el7_9 | Fixed | RHSA-2025:21657 |
| Red Hat Enterprise Linux 8 | libsoup-0:2.62.3-10.el8_10 | Fixed | RHSA-2025:19714 |
| Red Hat Enterprise Linux 8 | libsoup-0:2.62.3-10.el8_10 | Fixed | RHSA-2025:19714 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libsoup-0:2.62.3-1.el8_2.6 | Fixed | RHSA-2025:22013 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libsoup-0:2.62.3-2.el8_4.6 | Fixed | RHSA-2025:21772 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libsoup-0:2.62.3-2.el8_4.6 | Fixed | RHSA-2025:21772 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libsoup-0:2.62.3-2.el8_6.6 | Fixed | RHSA-2025:21664 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | libsoup-0:2.62.3-2.el8_6.6 | Fixed | RHSA-2025:21664 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | libsoup-0:2.62.3-2.el8_6.6 | Fixed | RHSA-2025:21664 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libsoup-0:2.62.3-3.el8_8.6 | Fixed | RHSA-2025:21665 |
| Red Hat Enterprise Linux 9 | libsoup-0:2.72.0-10.el9_6.3 | Fixed | RHSA-2025:19713 |
| Red Hat Enterprise Linux 9 | libsoup-0:2.72.0-12.el9_7.1 | Fixed | RHSA-2025:20959 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | libsoup-0:2.72.0-8.el9_0.6 | Fixed | RHSA-2025:21656 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libsoup-0:2.72.0-8.el9_2.6 | Fixed | RHSA-2025:21655 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | libsoup-0:2.72.0-8.el9_4.6 | Fixed | RHSA-2025:21666 |
| Red Hat Enterprise Linux 6 | libsoup | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate the risk associated with this libsoup vulnerability, Red Hat recommends avoiding interactions between client applications using the libsoup library and untrusted or compromised HTTP servers until a patched version of libsoup is deployed. Users and administrators should monitor their systems for suspicious HTTP activity and apply vendor updates as soon as a fix becomes available to prevent manipulation of cookie expiration logic that could lead to unexpected behavior or policy circumvention.
Red Hat statement
The Red Hat Product Security team has assessed the severity of this vulnerability as Low. This assessment is based on the fact that successful exploitation requires an attacker to control or manipulate the expiration date of cookies sent from a malicious or compromised HTTP server. Additionally, the consequences of a successful attack are limited in scope affecting only the handling of cookie lifetimes within the local client instance, with no direct impact on system integrity, data confidentiality, or availability.
Red Hat mitigation
To mitigate the risk associated with this libsoup vulnerability, Red Hat recommends avoiding interactions between client applications using the libsoup library and untrusted or compromised HTTP servers until a patched version of libsoup is deployed. Users and administrators should monitor their systems for suspicious HTTP activity and apply vendor updates as soon as a fix becomes available to prevent manipulation of cookie expiration logic that could lead to unexpected behavior or policy circumvention.
References (19)
- https://access.redhat.com/errata/RHSA-2025:19713 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:19714 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:19720 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:20959 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21032 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21655 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21656 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21657 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21664 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21665 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21666 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:21772 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:22013 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-4945 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2367175 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-16034 Advisory
- https://gitlab.gnome.org/GNOME/libsoup/-/issues/448 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-4945
- https://www.cve.org/CVERecord?id=CVE-2025-4945
Change history (0)
No recorded changes yet.