Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Ubuntu 24.10 USN-7126-1 critical: libsoup DoS & smuggling risks

ubuntu
Calendar Grey November 27, 2024
Scroller Ubuntu
Keep up-to-date with the latest advisory for Ubuntu Security Notice USN-7127-1, focusing on potential vulnerabilities within libxml and the essential patches to ensure system integrity.
Several security issues were fixed in libsoup.

Summary

Several security issues were fixed in libsoup.

Software Description:

- libsoup2.4: HTTP client/server library for GNOME

Details:

It was discovered that libsoup ignored certain characters at the end of

header names. A remote attacker could possibly use this issue to perform

a HTTP request smuggling attack. (CVE-2024-52530)

It was discovered that libsoup did not correctly handle memory while

performing UTF-8 conversions. An attacker could possibly use this issue

to cause a denial of service or execute arbitrary code. (CVE-2024-52531)

It was discovered that libsoup could enter an infinite loop when reading

certain websocket data. An attacker could possibly use this issue to

cause a denial of service. (CVE-2024-52532)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   libsoup-2.4-1                   2.74.3-7ubuntu0.1

Ubuntu 24.04 LTS
   libsoup-2.4-1                   2.74.3-6ubuntu1.1

Ubuntu 22.04 LTS
   libsoup2.4-1                    2.74.2-3ubuntu0.1

Ubuntu 20.04 LTS
   libsoup2.4-1                    2.70.0-1ubuntu0.1

Ubuntu 18.04 LTS
   libsoup2.4-1                    2.62.1-1ubuntu0.4+esm1
                                   Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-7126-1

  CVE-2024-52530, CVE-2024-52531, CVE-2024-52532

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7126-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.