关键漏洞信息 概述 发布日期: 2025-11-18 更新日期: 2025-11-18 类型/严重性: 重要 主题 更新适用于Red Hat Enterprise Linux 7 Extended Lifecycle Support的libsoup。 修复的安全问题 CVE-2025-2784: Heap buffer over-read when reading content. CVE-2025-32049: Denial of Service attack to websocket server. CVE-2025-32906: Out-of-bounds read in soup_headers_parse_request(). CVE-2025-32911: Double free in soup_message_headers_get_content_disposition(). CVE-2025-32913: NULL pointer dereference when "filename" parameter has no value in Content-Disposition header. CVE-2025-32914: Out-of-bounds Read leading to crash or exit of process. CVE-2025-4945: Integer Overflow in Cookie Expiration Date Handling. CVE-2025-4948: Integer Underflow leading to DoS. CVE-2025-11021: Out-of-Bounds Read in Cookie Date Handling. 受影响产品 Red Hat Enterprise Linux Server - Extended Lifecycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Lifecycle Support 7 s390x Red Hat Enterprise Linux Server - Extended Lifecycle Support for IBM Power (big endian and little endian)