Libsoup: integer overflow in cookie expiration date handling in libsoup
Summary
| CVE | CVE-2025-4945 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-05-19 17:15:29 UTC |
| Updated | 2026-06-30 11:16:23 UTC |
| Description | A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker to bypass cookie expiration logic, causing persistent or unintended cookie behavior. The issue stems from improper validation of large integer inputs during date arithmetic operations within the cookie parsing routines. |
Risk And Classification
Primary CVSS: v3.1 3.7 LOW from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.005380000 probability, percentile 0.413470000 (date 2026-07-02)
Problem Types: CWE-190 | CWE-190 Integer Overflow or Wraparound
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Enterprise Linux 10 | unaffected 0:3.6.5-3.el10_0.9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 10 | unaffected 0:3.6.5-3.el10_1.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | unaffected 0:2.62.2-9.el7_9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:2.62.3-10.el8_10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8 | unaffected 0:2.62.3-10.el8_10 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.2 Advanced Update Support | unaffected 0:2.62.3-1.el8_2.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | unaffected 0:2.62.3-2.el8_4.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | unaffected 0:2.62.3-2.el8_4.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | unaffected 0:2.62.3-2.el8_6.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | unaffected 0:2.62.3-2.el8_6.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions | unaffected 0:2.62.3-2.el8_6.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions | unaffected 0:2.62.3-3.el8_8.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:2.72.0-10.el9_6.3 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:2.72.0-12.el9_7.1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions | unaffected 0:2.72.0-8.el9_0.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions | unaffected 0:2.72.0-8.el9_2.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | unaffected 0:2.72.0-8.el9_4.6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Enterprise Linux 6 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2025:22013 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:20959 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21666 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:19714 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21665 | [email protected] | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2025-4945 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:19720 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21664 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21657 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:19713 | [email protected] | access.redhat.com | |
| gitlab.gnome.org/GNOME/libsoup/-/issues/448 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | gitlab.gnome.org | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21032 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21656 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21655 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2025:21772 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank fouzhe for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2025-05-19T04:35:01.994Z | Reported to Red Hat. |
| CNA | 2025-05-19T00:00:00.000Z | Made public. |
Workarounds
CNA: To mitigate the risk associated with this libsoup vulnerability, Red Hat recommends avoiding interactions between client applications using the libsoup library and untrusted or compromised HTTP servers until a patched version of libsoup is deployed. Users and administrators should monitor their systems for suspicious HTTP activity and apply vendor updates as soon as a fix becomes available to prevent manipulation of cookie expiration logic that could lead to unexpected behavior or policy circumvention.