关键信息 漏洞概述 公告编号: RHSA-2025:7505 类型/严重性: 重要 主题: libsoup3 安全更新 影响的产品 Red Hat Enterprise Linux for x86_64, ARM 64, IBM z Systems, Power, little endian 等多个版本和架构。 漏洞详情 CVE 编号: - CVE-2025-2784 - CVE-2025-32906 - CVE-2025-32908 - CVE-2025-32912 - CVE-2025-32914 - CVE-2025-46421 漏洞描述: - Heap buffer over-read in when sniffing content (CVE-2025-2784) - Out of bounds reads in (CVE-2025-32906) - Denial of service on libsoup through HTTP/2 server (CVE-2025-32908) - NULL pointer dereference in client when server omits the "nonce" parameter in an Unauthorized response with Digest authentication (CVE-2025-32912) - OOB Read on libsoup through function in soup-multipart.c leads to crash or exit of process (CVE-2025-32914) - Information disclosure may lead libsoup client sends Authorization header to a different host when being redirected by a server (CVE-2025-46421) 解决方案 参考链接: https://access.redhat.com/articles/12528 参考资料 Red Hat 安全更新分类