#1146714 libre: CVE-2026-50161

Package:
src:libre
Source:
src:libre
Submitter:
Salvatore Bonaccorso
Date:
2026-09-04 17:45:02 UTC
Severity:
normal
Tags:
#1146714#5
Date:
2026-09-04 17:44:00 UTC
From:
To:
Hi,

The following vulnerability was published for libre.

CVE-2026-50161[0]:
| libre is a generic library for real-time communications with
| asynchronous input and output support. Prior to 4.8.1, the
| websock_decode() function in src/websock/websock.c contains an
| integer overflow when validating a masked WebSocket frame that uses
| the 64-bit extended length encoding. The expression 4 + hdr->len can
| wrap when hdr->len is close to UINT64_MAX, causing the
| mbuf_get_left() bounds check to pass. The subsequent XOR unmasking
| loop then writes beyond the heap buffer. Applications using
| websock_accept() or websock_accept_proto() to implement a WebSocket
| server are affected, and exploitation can cause attacker-controlled
| heap corruption or denial of service after the HTTP WebSocket
| upgrade handshake. This issue is fixed in version 4.8.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-50161
https://www.cve.org/CVERecord?id=CVE-2026-50161
[1] https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h
[2] https://github.com/baresip/re/pull/1584
[3] https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8

Regards,
Salvatore