CVE-2025-46404

NameCVE-2025-46404
DescriptionA denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6058-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lasso (PTS)bullseye2.6.1-3vulnerable
bookworm2.8.1-1vulnerable
bookworm (security)2.8.1-1+deb12u1fixed
trixie2.8.2-9vulnerable
trixie (security)2.8.2-9+deb13u1fixed
sid, forky2.9.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lassosourcebookworm2.8.1-1+deb12u1DSA-6058-1
lassosourcetrixie2.8.2-9+deb13u1DSA-6058-1
lassosource(unstable)2.9.0-1

Notes

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2194
https://git.entrouvert.org/lasso.git/commit/?id=c880cad13732bcb50cbd9fa376ea39edb53e7d68 (v2.9.0)

Search for package or bug name: Reporting problems