Your message dated Sat, 12 Sep 2026 08:05:41 +0000
with message-id <[email protected]>
and subject line Released in 13.7
has caused the Debian Bug report #1146017,
regarding trixie-pu: libwebsockets/4.3.5-1+deb13u2
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1146017: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146017
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:libwebsockets
User: [email protected]
Usertags: pu
Hi RMs,
[ Reason ]
There are two low priority security fixes for libwebsockets that don't
warrant a DSA. One has a PoC and it can cause DoS on servers.
[ Impact ]
Users will no longer be a target for the CVE-2026-10650 and
CVE-2026-78161 security issues.
[ Tests ]
Build testing. Both fixes are already in Sid and passed autopkgtests.
[ Risks ]
Very small, the fixes are targeted, adding the required checks only.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in stable
[x] the issues are verified as fixed in unstable
Thanks,
Laszlo/GCS
diff -Nru libwebsockets-4.3.5/debian/changelog libwebsockets-4.3.5/debian/changelog
--- libwebsockets-4.3.5/debian/changelog 2025-11-04 00:02:18.000000000 +0100
+++ libwebsockets-4.3.5/debian/changelog 2026-08-27 18:56:33.000000000 +0200
@@ -1,3 +1,12 @@
+libwebsockets (4.3.5-1+deb13u2) trixie; urgency=medium
+
+ * Backport upstream security fix for CVE-2026-10650: resource consumption
+ in the lws_ssh_parse_plaintext() function (closes: #1139178).
+ * Backport upstream security fix for CVE-2026-78161: LECP CBOR position
+ out of bounds write (closes: #1145789).
+
+ -- Laszlo Boszormenyi (GCS) <[email protected]> Thu, 27 Aug 2026 18:56:33 +0200
+
libwebsockets (4.3.5-1+deb13u1) trixie; urgency=medium
* CVE-2025-11677 (Closes: #1118747)
diff -Nru libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch
--- libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch 1970-01-01 01:00:00.000000000 +0100
+++ libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch 2026-06-07 13:26:42.000000000 +0200
@@ -0,0 +1,43 @@
+From 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498 Mon Sep 17 00:00:00 2001
+From: Biniam F Demissie <[email protected]>
+Date: Wed, 13 May 2026 04:25:55 +0100
+Subject: [PATCH] ssh: plugin: add limit to resource exhaustion
+
+---
+ plugins/protocol_lws_ssh_base/sshd.c | 9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/plugins/ssh-base/sshd.c b/plugins/ssh-base/sshd.c
+index ea35cb8b7f..c849644d40 100644
+--- a/plugins/ssh-base/sshd.c
++++ b/plugins/ssh-base/sshd.c
+@@ -1,7 +1,7 @@
+ /*
+ * libwebsockets - small server side websockets and web server implementation
+ *
+- * Copyright (C) 2010 - 2019 Andy Green <[email protected]>
++ * Copyright (C) 2010 - 2026 Andy Green <[email protected]>
+ *
+ * Permission is hereby granted, free of charge, to any person obtaining a copy
+ * of this software and associated documentation files (the "Software"), to
+@@ -28,6 +28,8 @@
+ #include <string.h>
+ #include <stdlib.h>
+
++#define LWS_SSH_MAX_PACKET_SIZE (256 * 1024)
++
+ void *sshd_zalloc(size_t s)
+ {
+ void *p = malloc(s);
+@@ -592,6 +594,11 @@ lws_ssh_parse_plaintext(struct per_session_data__sshd *pss, uint8_t *p, size_t l
+ pss->parser_state = SSHS_MSG_PADDING;
+ pss->ctr = 0;
+ pss->pos = 4;
++
++ if (pss->msg_len > LWS_SSH_MAX_PACKET_SIZE) {
++ lwsl_notice("msg size %u exceeds maximum\n", pss->msg_len);
++ goto bail;
++ }
+ if (pss->msg_len < 2 + 4) {
+ lwsl_notice("illegal msg size\n");
+ goto bail;
diff -Nru libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch
--- libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch 1970-01-01 01:00:00.000000000 +0100
+++ libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch 2026-08-27 18:56:03.000000000 +0200
@@ -0,0 +1,42 @@
+From 1d44554a1bb262db63ff4e240152a9deecd99054 Mon Sep 17 00:00:00 2001
+From: Biniam F Demissie <[email protected]>
+Date: Mon, 6 Jul 2026 04:33:45 +0100
+Subject: [PATCH] cbor: overflow
+
+---
+ lib/misc/lecp.c | 11 ++++++-----
+ 1 file changed, 6 insertions(+), 5 deletions(-)
+
+diff --git a/lib/misc/lecp.c b/lib/misc/lecp.c
+index 44a7ac667..13e6ba476 100644
+--- a/lib/misc/lecp.c
++++ b/lib/misc/lecp.c
+@@ -325,11 +325,11 @@ report_raw_cbor(struct lecp_ctx *ctx)
+ if (!ctx->cbor_pos)
+ return 0;
+
++ ctx->cbor_pos = 0; /* reset BEFORE callback */
++
+ if (pst->cb(ctx, LECPCB_LITERAL_CBOR))
+ return 1;
+
+- ctx->cbor_pos = 0;
+-
+ return 0;
+ }
+
+@@ -388,10 +388,11 @@ lecp_parse(struct lecp_ctx *ctx, const uint8_t *cbor, size_t len)
+ */
+
+ if (ctx->literal_cbor_report) {
++ if (ctx->cbor_pos >= sizeof(ctx->cbor)) {
++ if (report_raw_cbor(ctx))
++ goto reject_callback;
++ }
+ ctx->cbor[ctx->cbor_pos++] = c;
+- if (ctx->cbor_pos == sizeof(ctx->cbor) &&
+- report_raw_cbor(ctx))
+- goto reject_callback;
+ }
+
+ switch (st->s) {
diff -Nru libwebsockets-4.3.5/debian/patches/series libwebsockets-4.3.5/debian/patches/series
--- libwebsockets-4.3.5/debian/patches/series 2025-11-04 00:02:18.000000000 +0100
+++ libwebsockets-4.3.5/debian/patches/series 2026-08-27 18:56:17.000000000 +0200
@@ -1,2 +1,4 @@
CVE-2025-11677.patch
CVE-2025-11678.patch
+CVE-2026-10650.patch
+CVE-2026-78161.patch
--- End Message ---
--- Begin Message ---
Version: 13.7
This update was released as part of 13.7.
--- End Message ---