USN-7932-1: libsoup vulnerability
USN-7932-1: libsoup vulnerability
Publication date: 15 December 2025
Overview: libsoup could be made to crash if it received specially crafted network traffic.
Packages
- libsoup3 - HTTP client/server library for GNOME
Details
It was discovered libsoup incorrectly handled memory when handling specific
HTTP/2 read and cancel sequences. An attacker could possibly use this issue
to cause a denial of service.
Update instructions
In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions:
- 25.10 questing libsoup-3.0-0 – 3.6.5-4ubuntu0.1
- 25.04 plucky libsoup-3.0-0 – 3.6.5-1ubuntu0.3
- 24.04 LTS noble libsoup-3.0-0 – 3.4.4-5ubuntu0.6
- 22.04 LTS jammy libsoup-3.0-0 – 3.0.7-0ubuntu1+esm6

