- Package:
- src:libwebsockets
- Source:
- src:libwebsockets
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-05 15:49:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libwebsockets. CVE-2026-78161[0]: | A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted | is the function report_raw_cbor of the file lib/misc/lecp.c of the | component LECP CBOR Recording. The manipulation results in out-of- | bounds write. The attack can be launched remotely. The exploit has | been made public and could be used. The patch is identified as | 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to | apply a patch to resolve this issue. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-78161 https://www.cve.org/CVERecord?id=CVE-2026-78161 [1] https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
libwebsockets, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145789@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated libwebsockets package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 27 Aug 2026 18:20:40 +0200
Source: libwebsockets
Architecture: source
Version: 4.3.5-6
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1145789
Changes:
libwebsockets (4.3.5-6) unstable; urgency=high
.
* Backport upstream security fix for CVE-2026-78161: LECP CBOR position
out of bounds write (closes: #1145789).
* Update watch file.
Checksums-Sha1:
e6022a60e8e361f6e05d029c32d9a23b8a55110a 2547 libwebsockets_4.3.5-6.dsc
478e5a515ae291c2e5f92e505055458a0d79341e 24848 libwebsockets_4.3.5-6.debian.tar.xz
Checksums-Sha256:
23cd9b2e854df9db2dd12b19b5163f9be083e28dcf7bc7e4979ff86ed78006a2 2547 libwebsockets_4.3.5-6.dsc
849457c151817b329bdca2393044a9ed26d6cf393814d23ee752ec63255de224 24848 libwebsockets_4.3.5-6.debian.tar.xz
Files:
5baf5673594fdec4e1507937507ae646 2547 libs optional libwebsockets_4.3.5-6.dsc
0f229d21766a7324e6ed16ff7eb678eb 24848 libs optional libwebsockets_4.3.5-6.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmqQa48ACgkQ3OMQ54ZM
yL+GJQ//aWbUcVS49ElZcf7oGHQQ49ar7UUmTe26KZofEOlS63Q9EO+6bjU3s8p4
Rzf96rvhMHROnFZohPsqxarhNG9PtvwXaYf11Z8q97tJeXGAGQkUm8MW0z3v6WtT
3pn+bz/pBhG+w6OA2hhXKxNCUIR+DOMPlvkKgd/ATc7GJHV1hsdU0+J35zjIqTDi
bnpWMIpaFb8louTQSW3QOKJH0COEcRnmS1Hp3sDDFY0OB6zv1ICmflV4Qp/4cQWL
PqObcwOar+FH1tKwVoyMadQO10et+dkyfhMF70++573j4st2q5FXoGCg4aqb0uj4
r+c5e3dS0zC3hUwSV7AWRq5cn22DGJOAFMRCUCBgyqAvH08+S0tMviQxCfsC5oaO
nBAiucIL+A5BUD9bxy8///cJF1GFAwehOsId1hnfHGLYlzrDBTdPEl5SfKits+xS
0OXw1GqnhNzI1aL0QejfDS81lzWnnktl/qvf1ZkR2steoaAIDrqXiFA3WUdlB7uV
zdVipfogi4fUB2XIvYwovDsJHDUTrug/DqVKEO36krPDeXtRjFxmuQU7ave9XfyK
QPV+ooEXMmVvL67eKI1/EeS1FhvLEWuayxGLEA+p/G607dCwwDY7fkNYVw/9AQ20
mzDu5RkBk3bqwKK/C8nOgptVlCEv7LZOUZ1voZDQ2/eKOmuzZHM=
=2wBt
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
libwebsockets, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1145789@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated libwebsockets package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 27 Aug 2026 18:56:33 +0200
Source: libwebsockets
Architecture: source
Version: 4.3.5-1+deb13u2
Distribution: trixie
Urgency: medium
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1139178 1145789
Changes:
libwebsockets (4.3.5-1+deb13u2) trixie; urgency=medium
.
* Backport upstream security fix for CVE-2026-10650: resource consumption
in the lws_ssh_parse_plaintext() function (closes: #1139178).
* Backport upstream security fix for CVE-2026-78161: LECP CBOR position
out of bounds write (closes: #1145789).
Checksums-Sha1:
a8f2dcb09a7b4b901835b868b4267d459656e425 2604 libwebsockets_4.3.5-1+deb13u2.dsc
d8bd965ae64410a42c24a45475a7ed4f67ac1552 20888 libwebsockets_4.3.5-1+deb13u2.debian.tar.xz
Checksums-Sha256:
999d0997cafed814b2b67efdb6add8875b88591ee00dd440586eebccb96a1727 2604 libwebsockets_4.3.5-1+deb13u2.dsc
059db96dc878057a629843e754fa56b2091186049c2bd36ba79db7fec62b8aea 20888 libwebsockets_4.3.5-1+deb13u2.debian.tar.xz
Files:
a6b26eaf8b6498cffbef523b4700d0f8 2604 libs optional libwebsockets_4.3.5-1+deb13u2.dsc
8c8a25961f7874010de50411be269096 20888 libs optional libwebsockets_4.3.5-1+deb13u2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmqbsuAACgkQ3OMQ54ZM
yL+Nxg/9GrCUq5dAhELZs6rlrYRsPC6OrjhPQxIUPci4XImanBhBNZL9ql7n69dt
tOTAASSoPuQQH9rrSzRfLmDcYFe1JUeanQTaL5mFJ9JBRfLIiBDwCz90IINv93nb
jeRiZv3MS+SkSvNZYo7ApHMZnC0FiTsmEI0AnFwcwiEMVLsna/z6VWuvUcamPmCS
lnq5EIF8hq/I4vycXcdCoxufEXCX+XhswH8OJRwulpe+31+5JQonAb8UEFSVm82s
3lpem6qxLh6QkYz60vPFQh/zSWZ5xUFlAekR0wVNlbwPBUwlkUHD4R9Evz7ryy9x
eQT0eG0jvj2bDSnL0FTYEWXfctN/dTvS67KBmcTHRkR2eKh8D0oCl023NLcw1jOI
Fv+cXzVBEJ+v6soKnbOofFhVgs4F1ImfWwPm302Ns1uDgWrg6l+DokAHgSdml20y
T5baVrxSJqE5ZfodEkRJbyJ/evrrHDEuiZqrMa4YV8fEnnEtMHkooDK8fcO+GGC7
6gAR+W/ryKtJx4qlstS9X84hvXU2d75uJ0z3IWThPqKZsKGXaYb9lB1tykhjGJA8
DpUCKsaxNYhMYbuasZL4xEsMWuxRM1zj4Go70bXmMJEZwHxxnpRP8Qm3ujbUIfgG
cQzFlZfgF3aJQhcW7LP2SzDoXG0w6gjZRGHNfsww80uk5DXS0NE=
=GkWr
-----END PGP SIGNATURE-----