#1146017 trixie-pu: libwebsockets/4.3.5-1+deb13u2

#1146017#5
Date:
2026-08-29 06:12:32 UTC
From:
To:
Hi RMs,

[ Reason ]
There are two low priority security fixes for libwebsockets that don't
warrant a DSA. One has a PoC and it can cause DoS on servers.

[ Impact ]
Users will no longer be a target for the CVE-2026-10650 and
CVE-2026-78161 security issues.

[ Tests ]
Build testing. Both fixes are already in Sid and passed autopkgtests.

[ Risks ]
Very small, the fixes are targeted, adding the required checks only.

[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in stable
[x] the issues are verified as fixed in unstable

Thanks,
Laszlo/GCS

#1146017#12
Date:
2026-09-04 11:10:50 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1146017#19
Date:
2026-09-05 15:42:28 UTC
From:
To:
package release.debian.org
tags 1146017 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: libwebsockets
Version: 4.3.5-1+deb13u2

Explanation: fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161]

#1146017#24
Date:
2026-09-05 15:42:28 UTC
From:
To:
package release.debian.org
tags 1146017 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: libwebsockets
Version: 4.3.5-1+deb13u2

Explanation: fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161]

#1146017#29
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.