关键漏洞信息 漏洞概述 公告编号: RHSA-2025:4560 发布日期: 2025-05-06 更新日期: 2025-05-06 类型/严重性: 安全公告 - 重要 影响的产品 Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 aarch64 固定的漏洞 CVE-2025-32050: libsoup: Integer overflow in append_param_quoted CVE-2025-32052: libsoup: Heap buffer overflow in sniff_unknown() CVE-2025-32053: libsoup: Heap buffer overflows in sniff_feed_or_html() and skip_insignificant_space() CVE-2025-32906: libsoup: Out of bounds reads in soup_headers_parse_request() CVE-2025-32911: libsoup: Double free on soup_message_headers_get_content_disposition() through "soup-message-headers.c" via "params" GHashTable value CVE-2025-32913: libsoup: NULL pointer dereference in soup_message_headers_get_content_disposition when "filename" parameter is present, but has no value in Content-Disposition header CVE-2025-46421: libsoup: Information disclosure may leads libsoup client sends Authorization header to a different host when being redirected by a server CVE-2025-46420: libsoup: Memory leak on soup_header_parse_quality_list() via soup-headers.c 解决方案 参考链接: https://access.redhat.com/articles/11258 参考资料 https://access.redhat.com/security/updates/classification/#important