We believe that the bug you reported is fixed in the latest version of
libwebsockets, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149178@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated libwebsockets package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 28 Sep 2026 07:19:09 +0200
Source: libwebsockets
Architecture: source
Version: 4.3.5-7
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1149178
Changes:
libwebsockets (4.3.5-7) unstable; urgency=high
.
* Backport upstream security fix for CVE-2026-19773: HTTP/2 HPACK Path
Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
(closes: #1149178).
Checksums-Sha1:
a81461ef608830484958e54a812c140a270ad404 2547 libwebsockets_4.3.5-7.dsc
551e268d73a6558102926828f25ff544ff307d70 25220 libwebsockets_4.3.5-7.debian.tar.xz
Checksums-Sha256:
36da3b323d9412e333740dbb5228452917d3348a94a72f9e966db21931b2c72e 2547 libwebsockets_4.3.5-7.dsc
2dc9a4dc17f6db275dab206b0c482b3f5e4d332ca092e94e974341af07fb5dbf 25220 libwebsockets_4.3.5-7.debian.tar.xz
Files:
350aed39353d538facc3e2dca6f210bd 2547 libs optional libwebsockets_4.3.5-7.dsc
07c38204388999f84d576157e2ce67e5 25220 libs optional libwebsockets_4.3.5-7.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmq5+gMACgkQ3OMQ54ZM
yL/W5w//SJNSt4ZusIDDUWmuPgbrN2ema+tesGUxJWgaZkHEYIfYSArSmj+k1ESv
P31LjkQ4OSfD2kXWis2ZkYmJu0l0Lj3MMyPnixFz8mtdSSFAPlCLmDasSOzekHa9
VzEImmWUkqw1OeOmyggh0Hj8w6+R8/RzO0kwpIlvvAZm8TOax0yoxv+VKdYtZj7D
T8am8rH7JMh5J9fmTeb6JWMn2gzr7YzNdMEJ3r3AywkN+Pgx505fZ/IwAw5LS2fC
CGc8ccHDUeht0yKBBEc9hjbB6LfKbaUT9sixk9iXPfgq8492c2rLWyrZ5wX4DClJ
oWr7SwETMf8upLPtqhqAz7MDliZjSnwskZOQEDJaLxTDrXuUjtMYP1A/ywIyv/ON
z16lMCVMgsOhAsO/1pOT84fmzlfaDxJ8N+qrqUZtqs92eNQgEM55E9QYGfJc0KjD
UwHPr/AfOHWvmvnJp86I+FzPsC8GetRfqyiYJeBnf3Y0QsT67wZAX3I3kdM5Ux7N
ZGyvzP/1IfD3pjy/xn+0mBhYw/APZlgy7iEkPE2+AZHmyyUpp09Ejs+ffmvGDESl
2GS4CXQLCtHhFS3oEdGUnaCtvi0ms9Uxt+qiub9mMcncKpu58JDP3/TFY4glQ1NJ
iu1xKvWMSMneqhguUBGjoYc+NV5Nc2eMcy5XcCEGOExL51y+xnk=
=tx4M
-----END PGP SIGNATURE-----