Bug 2521703 (CVE-2026-78161)

Summary: CVE-2026-78161 libwebsockets: libwebsockets: Out-of-bounds write in LECP CBOR Recording
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ansmith, anthomas, eglynn, ehelms, ggainey, jbritton, jjoyce, jpasqual, jpretori, jschluet, juwatts, lhh, mburns, mdellweg, mgarciac, mhulan, nmoumoul, osousa, pcreech, pjindal, rchan, smallamp, tmalecek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in warmcat libwebsockets. A remote attacker could exploit an out-of-bounds write vulnerability in the LECP CBOR Recording component, specifically within the `report_raw_cbor` function. This could lead to information disclosure, data corruption, or denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-24 01:01:33 UTC
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.