Use-After-Free Vulnerability in Libsoup Library for Network Applications
CVE-2025-12105
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 23 October 2025
What is CVE-2025-12105?
A flaw in the asynchronous message queue management of the libsoup library, extensively utilized in GNOME and WebKit applications, allows for problematic handling of HTTP/2 communications. This vulnerability arises when network operations are aborted under specific timing conditions, leading to a situation where an internal message queue item may be freed multiple times due to a lack of state synchronization. Consequently, this can result in a use-after-free memory access, potentially causing the affected applications to crash. Remote attackers could exploit this issue by carefully crafting specific HTTP/2 read and cancel sequences, which may ultimately lead to a denial-of-service scenario.
Affected Version(s)
Red Hat Enterprise Linux 10 0:3.6.5-3.el10_1.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved