Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:9559 - Security Advisory
Issued:
2024-11-13
Updated:
2024-11-13

RHSA-2024:9559 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libsoup security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libsoup is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libsoup packages provide an HTTP client and server library for GNOME.

Security Fix(es):

  • libsoup: infinite loop while reading websocket data (CVE-2024-52532)
  • libsoup: HTTP request smuggling via stripping null bytes from the ends of header names (CVE-2024-52530)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.6 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x

Fixes

  • BZ - 2325276 - CVE-2024-52532 libsoup: infinite loop while reading websocket data
  • BZ - 2325284 - CVE-2024-52530 libsoup: HTTP request smuggling via stripping null bytes from the ends of header names

CVEs

  • CVE-2024-52530
  • CVE-2024-52532

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
x86_64
libsoup-2.72.0-8.el9_5.2.i686.rpm SHA-256: ee76559d112b36dab27577bfbc577046027eeed0ba778cd8196ed888ce1e2442
libsoup-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a6f1144bd160e04126e121be045526341141609c9ed5ac114bb257b95d98dd4c
libsoup-debuginfo-2.72.0-8.el9_5.2.i686.rpm SHA-256: 2a86b7c0d00c60c5b8c7c6475e9a6513d21cfcde52fc8309506895b5ea7b0641
libsoup-debuginfo-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a7d52c31e9bc5f985adb66750136ce70771056b198f6c530657a369c97100d68
libsoup-debugsource-2.72.0-8.el9_5.2.i686.rpm SHA-256: adf2110b915d7bce0dffe934dedb7f75ee6979a5483e3379fd759d1d47dc7be7
libsoup-debugsource-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 64c9c72fc3e309f8395fcfcbc7a2ed7ff85df0dfd72a0713af29de4be0f53ebf
libsoup-devel-2.72.0-8.el9_5.2.i686.rpm SHA-256: 1fe58216a83ca0c6206278064f66c562c3f585baea5129122027b86f36897c86
libsoup-devel-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 01eb373758636a4d61a2a41481e2f57dfb606c99020c1d7bfb10fbbd2cf4bd7a

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
x86_64
libsoup-2.72.0-8.el9_5.2.i686.rpm SHA-256: ee76559d112b36dab27577bfbc577046027eeed0ba778cd8196ed888ce1e2442
libsoup-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a6f1144bd160e04126e121be045526341141609c9ed5ac114bb257b95d98dd4c
libsoup-debuginfo-2.72.0-8.el9_5.2.i686.rpm SHA-256: 2a86b7c0d00c60c5b8c7c6475e9a6513d21cfcde52fc8309506895b5ea7b0641
libsoup-debuginfo-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a7d52c31e9bc5f985adb66750136ce70771056b198f6c530657a369c97100d68
libsoup-debugsource-2.72.0-8.el9_5.2.i686.rpm SHA-256: adf2110b915d7bce0dffe934dedb7f75ee6979a5483e3379fd759d1d47dc7be7
libsoup-debugsource-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 64c9c72fc3e309f8395fcfcbc7a2ed7ff85df0dfd72a0713af29de4be0f53ebf
libsoup-devel-2.72.0-8.el9_5.2.i686.rpm SHA-256: 1fe58216a83ca0c6206278064f66c562c3f585baea5129122027b86f36897c86
libsoup-devel-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 01eb373758636a4d61a2a41481e2f57dfb606c99020c1d7bfb10fbbd2cf4bd7a

Red Hat Enterprise Linux Server - AUS 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
x86_64
libsoup-2.72.0-8.el9_5.2.i686.rpm SHA-256: ee76559d112b36dab27577bfbc577046027eeed0ba778cd8196ed888ce1e2442
libsoup-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a6f1144bd160e04126e121be045526341141609c9ed5ac114bb257b95d98dd4c
libsoup-debuginfo-2.72.0-8.el9_5.2.i686.rpm SHA-256: 2a86b7c0d00c60c5b8c7c6475e9a6513d21cfcde52fc8309506895b5ea7b0641
libsoup-debuginfo-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a7d52c31e9bc5f985adb66750136ce70771056b198f6c530657a369c97100d68
libsoup-debugsource-2.72.0-8.el9_5.2.i686.rpm SHA-256: adf2110b915d7bce0dffe934dedb7f75ee6979a5483e3379fd759d1d47dc7be7
libsoup-debugsource-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 64c9c72fc3e309f8395fcfcbc7a2ed7ff85df0dfd72a0713af29de4be0f53ebf
libsoup-devel-2.72.0-8.el9_5.2.i686.rpm SHA-256: 1fe58216a83ca0c6206278064f66c562c3f585baea5129122027b86f36897c86
libsoup-devel-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 01eb373758636a4d61a2a41481e2f57dfb606c99020c1d7bfb10fbbd2cf4bd7a

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
s390x
libsoup-2.72.0-8.el9_5.2.s390x.rpm SHA-256: ca9a9d78ad2239b9e676cd2a49e4ed85254e1d8f1c15fc10c9271c8206194258
libsoup-debuginfo-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 48d0260e5d721a543586de6ba3ab20a3a281e59d96883d96bfa54b4cae05c8d0
libsoup-debugsource-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 463fab87b9a1ad65c1e928c66cc29fe8b42ce2d488aa11c5dcc84816506dc513
libsoup-devel-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 739f4e19bb592bfea40cca573ad3d852f985b6212bda1ee20a3778cacfe969db

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
s390x
libsoup-2.72.0-8.el9_5.2.s390x.rpm SHA-256: ca9a9d78ad2239b9e676cd2a49e4ed85254e1d8f1c15fc10c9271c8206194258
libsoup-debuginfo-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 48d0260e5d721a543586de6ba3ab20a3a281e59d96883d96bfa54b4cae05c8d0
libsoup-debugsource-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 463fab87b9a1ad65c1e928c66cc29fe8b42ce2d488aa11c5dcc84816506dc513
libsoup-devel-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 739f4e19bb592bfea40cca573ad3d852f985b6212bda1ee20a3778cacfe969db

Red Hat Enterprise Linux for Power, little endian 9

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
ppc64le
libsoup-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 9b2993c2877c5e06edaee3745170c057ac784257179b05ba44a6e861db248887
libsoup-debuginfo-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: f11600273b68ea8a4296cffc98b0d01476900c75c080d1bb51d92de8549e76a2
libsoup-debugsource-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 18db8a599a2a4d2a9585aac3f20b7d78d4416e69117c75556786a43d792ea205
libsoup-devel-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 2190bb22612856c098ab07d36000e8b1a875ea0e65559c9880d81e93d506af99

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
ppc64le
libsoup-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 9b2993c2877c5e06edaee3745170c057ac784257179b05ba44a6e861db248887
libsoup-debuginfo-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: f11600273b68ea8a4296cffc98b0d01476900c75c080d1bb51d92de8549e76a2
libsoup-debugsource-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 18db8a599a2a4d2a9585aac3f20b7d78d4416e69117c75556786a43d792ea205
libsoup-devel-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 2190bb22612856c098ab07d36000e8b1a875ea0e65559c9880d81e93d506af99

Red Hat Enterprise Linux for ARM 64 9

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
aarch64
libsoup-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: a29a4e707271fe215e77bcb12f47d9af2db35936687e643f4898980f6f11ec61
libsoup-debuginfo-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: db41e1aa39b8533b3b59d6d6bb124436800cffb81ef386f2d43c95a83023e783
libsoup-debugsource-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: f662591fce2bfb3d4bc4d0f76c3b5012d88df60d688b85d0137c0215e03df6c0
libsoup-devel-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: cc031c5e0f3090562a66fcc208f109506ef4c48bd27a2ad358e1806d7592a617

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
aarch64
libsoup-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: a29a4e707271fe215e77bcb12f47d9af2db35936687e643f4898980f6f11ec61
libsoup-debuginfo-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: db41e1aa39b8533b3b59d6d6bb124436800cffb81ef386f2d43c95a83023e783
libsoup-debugsource-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: f662591fce2bfb3d4bc4d0f76c3b5012d88df60d688b85d0137c0215e03df6c0
libsoup-devel-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: cc031c5e0f3090562a66fcc208f109506ef4c48bd27a2ad358e1806d7592a617

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
ppc64le
libsoup-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 9b2993c2877c5e06edaee3745170c057ac784257179b05ba44a6e861db248887
libsoup-debuginfo-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: f11600273b68ea8a4296cffc98b0d01476900c75c080d1bb51d92de8549e76a2
libsoup-debugsource-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 18db8a599a2a4d2a9585aac3f20b7d78d4416e69117c75556786a43d792ea205
libsoup-devel-2.72.0-8.el9_5.2.ppc64le.rpm SHA-256: 2190bb22612856c098ab07d36000e8b1a875ea0e65559c9880d81e93d506af99

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
x86_64
libsoup-2.72.0-8.el9_5.2.i686.rpm SHA-256: ee76559d112b36dab27577bfbc577046027eeed0ba778cd8196ed888ce1e2442
libsoup-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a6f1144bd160e04126e121be045526341141609c9ed5ac114bb257b95d98dd4c
libsoup-debuginfo-2.72.0-8.el9_5.2.i686.rpm SHA-256: 2a86b7c0d00c60c5b8c7c6475e9a6513d21cfcde52fc8309506895b5ea7b0641
libsoup-debuginfo-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: a7d52c31e9bc5f985adb66750136ce70771056b198f6c530657a369c97100d68
libsoup-debugsource-2.72.0-8.el9_5.2.i686.rpm SHA-256: adf2110b915d7bce0dffe934dedb7f75ee6979a5483e3379fd759d1d47dc7be7
libsoup-debugsource-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 64c9c72fc3e309f8395fcfcbc7a2ed7ff85df0dfd72a0713af29de4be0f53ebf
libsoup-devel-2.72.0-8.el9_5.2.i686.rpm SHA-256: 1fe58216a83ca0c6206278064f66c562c3f585baea5129122027b86f36897c86
libsoup-devel-2.72.0-8.el9_5.2.x86_64.rpm SHA-256: 01eb373758636a4d61a2a41481e2f57dfb606c99020c1d7bfb10fbbd2cf4bd7a

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
aarch64
libsoup-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: a29a4e707271fe215e77bcb12f47d9af2db35936687e643f4898980f6f11ec61
libsoup-debuginfo-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: db41e1aa39b8533b3b59d6d6bb124436800cffb81ef386f2d43c95a83023e783
libsoup-debugsource-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: f662591fce2bfb3d4bc4d0f76c3b5012d88df60d688b85d0137c0215e03df6c0
libsoup-devel-2.72.0-8.el9_5.2.aarch64.rpm SHA-256: cc031c5e0f3090562a66fcc208f109506ef4c48bd27a2ad358e1806d7592a617

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6

SRPM
libsoup-2.72.0-8.el9_5.2.src.rpm SHA-256: c5420465468b7672a71ca5b6ad87bf3c55b86731a79dfbd48aa282c111bd1dce
s390x
libsoup-2.72.0-8.el9_5.2.s390x.rpm SHA-256: ca9a9d78ad2239b9e676cd2a49e4ed85254e1d8f1c15fc10c9271c8206194258
libsoup-debuginfo-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 48d0260e5d721a543586de6ba3ab20a3a281e59d96883d96bfa54b4cae05c8d0
libsoup-debugsource-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 463fab87b9a1ad65c1e928c66cc29fe8b42ce2d488aa11c5dcc84816506dc513
libsoup-devel-2.72.0-8.el9_5.2.s390x.rpm SHA-256: 739f4e19bb592bfea40cca573ad3d852f985b6212bda1ee20a3778cacfe969db

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility