CVE-2025-12105
published 2025-10-23CVE-2025-12105: A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
34.5th percentile
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libsoup2.4 | < libsoup3 3.6.5-6 (forky) | libsoup3 3.6.5-6 (forky) |
| debian | libsoup3 | < libsoup3 3.6.5-6 (forky) | libsoup3 3.6.5-6 (forky) |
| gnome | libsoup | <= 3.6.5 | — |
| msrc | azl3_libsoup_3.4.4-10_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libsoup vulnerability
vendor_ubuntu·2025-12-15
CVE-2025-12105 libsoup vulnerability
Title: libsoup vulnerability
Summary: libsoup could be made to crash if it received specially crafted network
traffic.
It was discovered libsoup incorrectly handled memory when handling specific
HTTP/2 read and cancel sequences. An attacker could possibly use this issue
to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libsoup: Heap Use-After-Free in libsoup message queue handling during HTTP/2 read completion
vendor_redhat·2025-10-23·CVSS 7.5
CVE-2025-12105 [HIGH] CWE-416 libsoup: Heap Use-After-Free in libsoup message queue handling during HTTP/2 read completion
libsoup: Heap Use-After-Free in libsoup message queue handling during HTTP/2 read completion
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to mana
Microsoft
Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
vendor_msrc·2025-10-14·CVSS 7.5
CVE-2025-12105 [HIGH] CWE-416 Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
Libsoup: heap use-after-free in libsoup message queue handling during http/2 read completion
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-12105: libsoup2.4 - A flaw was found in the asynchronous message queue handling of the libsoup libra...
vendor_debian·2025·CVSS 7.5
CVE-2025-12105 [HIGH] CVE-2025-12105: libsoup2.4 - A flaw was found in the asynchronous message queue handling of the libsoup libra...
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.
Scope: local
bookworm: resolved
bullseye: resolved
trixie: resolved
OSV
CVE-2025-12105: A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/
osv·2025-10-23·CVSS 7.5
CVE-2025-12105 [HIGH] CVE-2025-12105: A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.
GHSA
GHSA-gppq-jw9r-4v4j: A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/
ghsa_unreviewed·2025-10-23
CVE-2025-12105 [HIGH] CWE-416 GHSA-gppq-jw9r-4v4j: A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state synchronization. This leads to a use-after-free memory access, potentially crashing the affected application. Attackers could exploit this behavior remotely by triggering specific HTTP/2 read and cancel sequences, resulting in a denial-of-service condition.
Suricata
ET WEB_SPECIFIC_APPS Progress WhatsUp Gold SnmpExtendedActiveMonitor Path Traversal Vulnerability (CVE-2024-12105)
suricata·2025-01-22·CVSS 6.5
CVE-2024-12105 [MEDIUM] ET WEB_SPECIFIC_APPS Progress WhatsUp Gold SnmpExtendedActiveMonitor Path Traversal Vulnerability (CVE-2024-12105)
ET WEB_SPECIFIC_APPS Progress WhatsUp Gold SnmpExtendedActiveMonitor Path Traversal Vulnerability (CVE-2024-12105)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Progress WhatsUp Gold SnmpExtendedActiveMonitor Path Traversal Vulnerability (CVE-2024-12105)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/NmConsole/api/core/snmpextendedactivemonitor|3f|xmlFileName|3d|"; fast_pattern; startswith; pcre:"/^[^\x26]*?(?:(?:\x2e|%2[Ee]){1,2}(?:\x2f|\x5c|%5[Cc]|%2[Ff]){1,}){2,}/R"; reference:cve,2024-12105; reference:url,talosintelligence.com/vulnerability_reports/TALOS-2024-2089; classtype:attempted-admin; sid:2059437; rev:1; metadata:affected_product WhatsUp_Gold, attack_target Web_Server, tls_state TLSDecrypt, created_at 2025_01_22, cve CVE_202
No public exploits indexed.
2025-10-23
Published