Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Debian 11: Libwebsockets Critical DoS and Buffer Overflow DLA-4373-1

debian lts
Calendar Grey November 17, 2025
Dist Debian Esm H88
Critical security update for libwebsockets addresses denial of service and buffer overflow vulnerabilities in Debian LTS.
Libwebsockets (LWS) is a flexible, lightweight pure C library for implementing modern network protocols easily with a tiny footprint, using a nonblocking event loop

Summary

CVE-2025-11677

Use After Free in WebSocket server implementation in
lws_handshake_server in warmcat libwebsockets may allow an attacker,
in specific configurations where the user provides a callback
function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve
denial of service.

CVE-2025-11678

Stack-based Buffer Overflow in lws_adns_parse_label in warmcat
libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is
enabled during compilation, to overflow the label_stack, when the
attacker is able to sniff a DNS request in order to craft a response
with a matching ID containing a label longer than the maximum.

For Debian 11 bullseye, these problems have been fixed in version
4.0.20-2+deb11u1.

We recommend that you upgrade your libwebsockets packages.

For the detailed security status of libwebsockets please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libwebsockets

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libwebsockets
Version: 4.0.20-2+deb11u1
CVE ID: CVE-2025-11677 CVE-2025-11678
Debian Bug: 1118746 1118747

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here