CVE-2025-46784

NameCVE-2025-46784
DescriptionA denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a memory depletion, resulting in denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lasso (PTS)bullseye2.6.1-3vulnerable
bookworm2.8.1-1fixed
bookworm (security)2.8.1-1+deb12u1fixed
trixie2.8.2-9fixed
trixie (security)2.8.2-9+deb13u1fixed
forky, sid2.9.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lassosource(unstable)2.8.1-1

Notes

https://talosintelligence.com/vulnerability_reports/TALOS-2025-2195
https://git.entrouvert.org/lasso.git/commit/?id=8a588a8acb4a9cb7c7cb4dfd91a8278264a6d15a (v2.8.1)

Search for package or bug name: Reporting problems