Bug#1146017: trixie-pu: libwebsockets/4.3.5-1+deb13u2

László Böszörményi (GCS) <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <CAKjSHr32CJGx7aCr4OdTDLCW_T76MrsX09vNuUuTXP6jyZme-Q__5564.05582917563$1787984136$gmane$org@mail.gmail.com>
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:libwebsockets
User: [email protected]
Usertags: pu

Hi RMs,

[ Reason ]
There are two low priority security fixes for libwebsockets that don't
warrant a DSA. One has a PoC and it can cause DoS on servers.

[ Impact ]
Users will no longer be a target for the CVE-2026-10650 and
CVE-2026-78161 security issues.

[ Tests ]
Build testing. Both fixes are already in Sid and passed autopkgtests.

[ Risks ]
Very small, the fixes are targeted, adding the required checks only.

[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in stable
[x] the issues are verified as fixed in unstable

Thanks,
Laszlo/GCS
libwebsockets_4.3.5-1+deb13u1_to_4.3.5-1+deb13u2.patch (text/x-patch, 4.3 KB)
diff -Nru libwebsockets-4.3.5/debian/changelog libwebsockets-4.3.5/debian/changelog
--- libwebsockets-4.3.5/debian/changelog	2025-11-04 00:02:18.000000000 +0100
+++ libwebsockets-4.3.5/debian/changelog	2026-08-27 18:56:33.000000000 +0200
@@ -1,3 +1,12 @@
+libwebsockets (4.3.5-1+deb13u2) trixie; urgency=medium
+
+  * Backport upstream security fix for CVE-2026-10650: resource consumption
+    in the lws_ssh_parse_plaintext() function (closes: #1139178).
+  * Backport upstream security fix for CVE-2026-78161: LECP CBOR position
+    out of bounds write (closes: #1145789).
+
+ -- Laszlo Boszormenyi (GCS) <[email protected]>  Thu, 27 Aug 2026 18:56:33 +0200
+
 libwebsockets (4.3.5-1+deb13u1) trixie; urgency=medium
 
   * CVE-2025-11677 (Closes: #1118747)
diff -Nru libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch
--- libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch	1970-01-01 01:00:00.000000000 +0100
+++ libwebsockets-4.3.5/debian/patches/CVE-2026-10650.patch	2026-06-07 13:26:42.000000000 +0200
@@ -0,0 +1,43 @@
+From 3f9f0c6ecaf0e6f3f219d30632c5d1f2479d7498 Mon Sep 17 00:00:00 2001
+From: Biniam F Demissie <[email protected]>
+Date: Wed, 13 May 2026 04:25:55 +0100
+Subject: [PATCH] ssh: plugin: add limit to resource exhaustion
+
+---
+ plugins/protocol_lws_ssh_base/sshd.c | 9 ++++++++-
+ 1 file changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/plugins/ssh-base/sshd.c b/plugins/ssh-base/sshd.c
+index ea35cb8b7f..c849644d40 100644
+--- a/plugins/ssh-base/sshd.c
++++ b/plugins/ssh-base/sshd.c
+@@ -1,7 +1,7 @@
+ /*
+  * libwebsockets - small server side websockets and web server implementation
+  *
+- * Copyright (C) 2010 - 2019 Andy Green <[email protected]>
++ * Copyright (C) 2010 - 2026 Andy Green <[email protected]>
+  *
+  * Permission is hereby granted, free of charge, to any person obtaining a copy
+  * of this software and associated documentation files (the "Software"), to
+@@ -28,6 +28,8 @@
+ #include <string.h>
+ #include <stdlib.h>
+ 
++#define LWS_SSH_MAX_PACKET_SIZE  (256 * 1024)
++
+ void *sshd_zalloc(size_t s)
+ {
+ 	void *p = malloc(s);
+@@ -592,6 +594,11 @@ lws_ssh_parse_plaintext(struct per_session_data__sshd *pss, uint8_t *p, size_t l
+ 			pss->parser_state = SSHS_MSG_PADDING;
+ 			pss->ctr = 0;
+ 			pss->pos = 4;
++
++			if (pss->msg_len > LWS_SSH_MAX_PACKET_SIZE) {
++				lwsl_notice("msg size %u exceeds maximum\n", pss->msg_len);
++				goto bail;
++			}
+ 			if (pss->msg_len < 2 + 4) {
+ 				lwsl_notice("illegal msg size\n");
+ 				goto bail;
diff -Nru libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch
--- libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch	1970-01-01 01:00:00.000000000 +0100
+++ libwebsockets-4.3.5/debian/patches/CVE-2026-78161.patch	2026-08-27 18:56:03.000000000 +0200
@@ -0,0 +1,42 @@
+From 1d44554a1bb262db63ff4e240152a9deecd99054 Mon Sep 17 00:00:00 2001
+From: Biniam F Demissie <[email protected]>
+Date: Mon, 6 Jul 2026 04:33:45 +0100
+Subject: [PATCH] cbor: overflow
+
+---
+ lib/misc/lecp.c | 11 ++++++-----
+ 1 file changed, 6 insertions(+), 5 deletions(-)
+
+diff --git a/lib/misc/lecp.c b/lib/misc/lecp.c
+index 44a7ac667..13e6ba476 100644
+--- a/lib/misc/lecp.c
++++ b/lib/misc/lecp.c
+@@ -325,11 +325,11 @@ report_raw_cbor(struct lecp_ctx *ctx)
+ 	if (!ctx->cbor_pos)
+ 		return 0;
+ 
++	ctx->cbor_pos = 0;                /* reset BEFORE callback */
++
+ 	if (pst->cb(ctx, LECPCB_LITERAL_CBOR))
+ 		return 1;
+ 
+-	ctx->cbor_pos = 0;
+-
+ 	return 0;
+ }
+ 
+@@ -388,10 +388,11 @@ lecp_parse(struct lecp_ctx *ctx, const uint8_t *cbor, size_t len)
+ 		 */
+ 
+ 		if (ctx->literal_cbor_report) {
++			if (ctx->cbor_pos >= sizeof(ctx->cbor)) {
++				if (report_raw_cbor(ctx))
++					goto reject_callback;
++			}
+ 			ctx->cbor[ctx->cbor_pos++] = c;
+-			if (ctx->cbor_pos == sizeof(ctx->cbor) &&
+-			    report_raw_cbor(ctx))
+-				goto reject_callback;
+ 		}
+ 
+ 		switch (st->s) {
diff -Nru libwebsockets-4.3.5/debian/patches/series libwebsockets-4.3.5/debian/patches/series
--- libwebsockets-4.3.5/debian/patches/series	2025-11-04 00:02:18.000000000 +0100
+++ libwebsockets-4.3.5/debian/patches/series	2026-08-27 18:56:17.000000000 +0200
@@ -1,2 +1,4 @@
 CVE-2025-11677.patch
 CVE-2025-11678.patch
+CVE-2026-10650.patch
+CVE-2026-78161.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.