cbcvebase.
CVE-2024-52532
published 2024-11-11

CVE-2024-52532: GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlibsoup2.4< libsoup2.4 2.74.3-1+deb12u1 (bookworm)libsoup2.4 2.74.3-1+deb12u1 (bookworm)
debianlibsoup3< libsoup2.4 2.74.3-1+deb12u1 (bookworm)libsoup2.4 2.74.3-1+deb12u1 (bookworm)
gnomelibsoup< 3.6.13.6.1
msrcazl3_libsoup_3.4.4-2_on_azure_linux_3.0
msrcazl3_libsoup_3.4.4-6_on_azure_linux_3.0
msrccbl2_libsoup_3.0.4-2_on_cbl_mariner_2.0
msrccbl2_libsoup_3.0.4-6_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH