Your message dated Thu, 27 Aug 2026 17:05:05 +0000
with message-id <[email protected]>
and subject line Bug#1145789: fixed in libwebsockets 4.3.5-6
has caused the Debian Bug report #1145789,
regarding libwebsockets: CVE-2026-78161
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1145789: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145789
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libwebsockets
Version: 4.3.5-5
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libwebsockets.
CVE-2026-78161[0]:
| A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted
| is the function report_raw_cbor of the file lib/misc/lecp.c of the
| component LECP CBOR Recording. The manipulation results in out-of-
| bounds write. The attack can be launched remotely. The exploit has
| been made public and could be used. The patch is identified as
| 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to
| apply a patch to resolve this issue.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-78161
https://www.cve.org/CVERecord?id=CVE-2026-78161
[1]
https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libwebsockets
Source-Version: 4.3.5-6
Done: Laszlo Boszormenyi (GCS) <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libwebsockets, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <[email protected]> (supplier of updated libwebsockets
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 27 Aug 2026 18:20:40 +0200
Source: libwebsockets
Architecture: source
Version: 4.3.5-6
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <[email protected]>
Changed-By: Laszlo Boszormenyi (GCS) <[email protected]>
Closes: 1145789
Changes:
libwebsockets (4.3.5-6) unstable; urgency=high
.
* Backport upstream security fix for CVE-2026-78161: LECP CBOR position
out of bounds write (closes: #1145789).
* Update watch file.
Checksums-Sha1:
e6022a60e8e361f6e05d029c32d9a23b8a55110a 2547 libwebsockets_4.3.5-6.dsc
478e5a515ae291c2e5f92e505055458a0d79341e 24848
libwebsockets_4.3.5-6.debian.tar.xz
Checksums-Sha256:
23cd9b2e854df9db2dd12b19b5163f9be083e28dcf7bc7e4979ff86ed78006a2 2547
libwebsockets_4.3.5-6.dsc
849457c151817b329bdca2393044a9ed26d6cf393814d23ee752ec63255de224 24848
libwebsockets_4.3.5-6.debian.tar.xz
Files:
5baf5673594fdec4e1507937507ae646 2547 libs optional libwebsockets_4.3.5-6.dsc
0f229d21766a7324e6ed16ff7eb678eb 24848 libs optional
libwebsockets_4.3.5-6.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmqQa48ACgkQ3OMQ54ZM
yL+GJQ//aWbUcVS49ElZcf7oGHQQ49ar7UUmTe26KZofEOlS63Q9EO+6bjU3s8p4
Rzf96rvhMHROnFZohPsqxarhNG9PtvwXaYf11Z8q97tJeXGAGQkUm8MW0z3v6WtT
3pn+bz/pBhG+w6OA2hhXKxNCUIR+DOMPlvkKgd/ATc7GJHV1hsdU0+J35zjIqTDi
bnpWMIpaFb8louTQSW3QOKJH0COEcRnmS1Hp3sDDFY0OB6zv1ICmflV4Qp/4cQWL
PqObcwOar+FH1tKwVoyMadQO10et+dkyfhMF70++573j4st2q5FXoGCg4aqb0uj4
r+c5e3dS0zC3hUwSV7AWRq5cn22DGJOAFMRCUCBgyqAvH08+S0tMviQxCfsC5oaO
nBAiucIL+A5BUD9bxy8///cJF1GFAwehOsId1hnfHGLYlzrDBTdPEl5SfKits+xS
0OXw1GqnhNzI1aL0QejfDS81lzWnnktl/qvf1ZkR2steoaAIDrqXiFA3WUdlB7uV
zdVipfogi4fUB2XIvYwovDsJHDUTrug/DqVKEO36krPDeXtRjFxmuQU7ave9XfyK
QPV+ooEXMmVvL67eKI1/EeS1FhvLEWuayxGLEA+p/G607dCwwDY7fkNYVw/9AQ20
mzDu5RkBk3bqwKK/C8nOgptVlCEv7LZOUZ1voZDQ2/eKOmuzZHM=
=2wBt
-----END PGP SIGNATURE-----
pgp1z9i2IwhDH.pgp
Description: PGP signature
--- End Message ---