- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- László Böszörményi
- Date:
- 2026-09-12 08:07:40 UTC
- Severity:
- normal
- Tags:
Hi RMs, [ Reason ] There are two low priority security fixes for libwebsockets that don't warrant a DSA. One has a PoC and it can cause DoS on servers. [ Impact ] Users will no longer be a target for the CVE-2026-10650 and CVE-2026-78161 security issues. [ Tests ] Build testing. Both fixes are already in Sid and passed autopkgtests. [ Risks ] Very small, the fixes are targeted, adding the required checks only. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in stable [x] the issues are verified as fixed in unstable Thanks, Laszlo/GCS
Control: tags -1 + confirmed Please go ahead. Regards, Adam
package release.debian.org tags 1146017 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: libwebsockets Version: 4.3.5-1+deb13u2 Explanation: fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161]
package release.debian.org tags 1146017 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: libwebsockets Version: 4.3.5-1+deb13u2 Explanation: fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161]
This update was released as part of 13.7.