Memory Leak Vulnerability in libsoup Affects Red Hat Products
CVE-2025-46420

6.5MEDIUM

What is CVE-2025-46420?

A memory leak has been identified in the libsoup library, specifically within the soup_header_parse_quality_list() function. This vulnerability occurs when parsing a quality list that improperly includes elements set to zero, potentially leading to inefficient memory usage and application performance degradation over time. Users of affected versions are advised to take immediate action to mitigate potential impacts.

Affected Version(s)

Red Hat Enterprise Linux 8 0:2.62.3-8.el8_10

Red Hat Enterprise Linux 8 0:2.62.3-8.el8_10

Red Hat Enterprise Linux 8.2 Advanced Update Support 0:2.62.3-1.el8_2.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-46420 : Memory Leak Vulnerability in libsoup Affects Red Hat Products