Critical Vulnerability Information Vulnerability Overview Advisory ID: RHSA-2025:4560 Release Date: 2025-05-06 Update Date: 2025-05-06 Type/Severity: Security Advisory - Important Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 aarch64 Fixed Vulnerabilities CVE-2025-32050: libsoup: Integer overflow in append_param_quoted CVE-2025-32052: libsoup: Heap buffer overflow in sniff_unknown() CVE-2025-32053: libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() CVE-2025-32906: libsoup: Out of bounds reads in soup_headers_parse_request() CVE-2025-32911: libsoup: Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value CVE-2025-32913: libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header CVE-2025-46421: libsoup: Information disclosure may lead libsoup client to send Authorization header to a different host when being redirected by a server CVE-2025-46420: libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c Solution Reference Link: https://access.redhat.com/articles/11258 References https://access.redhat.com/security/updates/classification/#important