AlmaLinux 9.2 [TuxCare] Security Update: libsoup / libsoup-devel / libsoup-doc Multiple Vulnerabilities (ALMALINUX9.2:CLSA-2025:1749569869)

medium Nessus Plugin ID 352783

Synopsis

The AlmaLinux host is missing one or more security updates.

Description

The AlmaLinux 9.2 host has packages installed that are affected by multiple vulnerabilities as referenced in the TuxCare ALMALINUX9.2:CLSA-2025:1749569869 advisory.

- A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. (CVE-2025-2784)

- A flaw was found in libsoup. The libsoup append_param_quoted() function may contain an overflow bug resulting in a buffer under-read. (CVE-2025-32050)

- A flaw was found in libsoup. A vulnerability in the sniff_unknown() function may lead to heap buffer over- read. (CVE-2025-32052)

- A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out- of-bounds read. This flaw allows a malicious HTTP client to induce the libsoup server to read out of bounds. (CVE-2025-32914)

- A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes. (CVE-2025-46420)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in TuxCare advisory ALMALINUX9.2:CLSA-2025:1749569869.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2025:1749569869

http://www.nessus.org/u?80c4e57f

Plugin Details

Severity: Medium

ID: 352783

File Name: tuxcare_alma_linux_9.2_CLSA-2025-1749569869.nasl

Version: 1.1

Type: Local

Published: 9/30/2026

Updated: 9/30/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.23

Vendor

Vendor Severity: Important

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2025-2784

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/OS/extended-third-party, Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/10/2025

Vulnerability Publication Date: 4/3/2025

Reference Information

CVE: CVE-2025-2784, CVE-2025-32050, CVE-2025-32052, CVE-2025-32914, CVE-2025-46420, CVE-2025-4948

CLSA: 2025:1749569869