CVE-2025-11677
Use After Free in WebSocket server implementation in
lws_handshake_server in warmcat libwebsockets may allow an attacker,
in specific configurations where the user provides a callback
function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve
denial of service.
CVE-2025-11678
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat
libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is
enabled during compilation, to overflow the label_stack, when the
attacker is able to sniff a DNS request in order to craft a response
with a matching ID containing a label longer than the maximum.
For Debian 11 bullseye, these problems have been fixed in version
4.0.20-2+deb11u1.
We recommend that you upgrade your libwebsockets packages.
For the detailed security status of libwebsockets please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libwebsockets
Get the latest Linux and open source security news straight to your inbox.