CVE-2025-11677

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2025-11677 NameCVE-2025-11677 DescriptionUse After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat,…

CVE-2025-11677

NameCVE-2025-11677
DescriptionUse After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4373-1
Debian Bugs1118747

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libwebsockets (PTS)bullseye4.0.20-2vulnerable
bullseye (security)4.0.20-2+deb11u1fixed
bookworm4.1.6-3vulnerable
trixie4.3.5-1+deb13u1fixed
forky4.3.5-4.1fixed
sid4.3.5-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libwebsocketssourcebullseye4.0.20-2+deb11u1DLA-4373-1
libwebsocketssourcetrixie4.3.5-1+deb13u1
libwebsocketssource(unstable)4.3.5-31118747

Notes

[bookworm] - libwebsockets <no-dsa> (Minor issue)
https://libwebsockets.org/git/libwebsockets/commit?id=2f082ec31261f556969160143ba94875d783971a

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[bookworm] - libwebsockets <no-dsa> (Minor issue)https://libwebsockets.org/git/libwebsockets/commit?id=2f082ec31261f556969160143ba94875d783971a

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 4.3.5-1+deb13u1
sid Fixed 4.3.5-3
forky Fixed 4.3.5-3
bullseye Fixed 4.0.20-2+deb11u1
bookworm Affected

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.