{"id":"UBUNTU-CVE-2025-7370","details":"A flaw was found in libsoup. A NULL pointer dereference vulnerability occurs in libsoup's cookie parsing functionality. When processing a cookie without a domain parameter, the soup_cookie_jar_add_cookie() function will crash, resulting in a denial of service.","modified":"2025-07-14T04:44:40Z","published":"2025-07-10T15:15:00Z","withdrawn":"2025-07-16T17:15:59Z","upstream":["CVE-2025-7370"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-7370"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-7370"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/libsoup/-/issues/430"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2378888"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-7370"}],"affected":[{"package":{"name":"libsoup3","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libsoup3@3.0.7-0ubuntu1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.0.4-2","3.0.4-3","3.0.5-1","3.0.7-0ubuntu1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-7370.json"}},{"package":{"name":"libsoup3","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libsoup3@3.4.4-5ubuntu0.4?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.4.2-4","3.4.4-1","3.4.4-2","3.4.4-4","3.4.4-5","3.4.4-5build1","3.4.4-5build2","3.4.4-5ubuntu0.1","3.4.4-5ubuntu0.2","3.4.4-5ubuntu0.3","3.4.4-5ubuntu0.4"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-7370.json"}},{"package":{"name":"libsoup3","ecosystem":"Ubuntu:25.04","purl":"pkg:deb/ubuntu/libsoup3@3.6.5-1ubuntu0.1?arch=source&distro=plucky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.6.0-2","3.6.0-3","3.6.0-4","3.6.1-1","3.6.4-1","3.6.4-2","3.6.4-3","3.6.5-1","3.6.5-1ubuntu0.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-7370.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}