Bug 2521703 (CVE-2026-78161) - CVE-2026-78161 libwebsockets: libwebsockets: Out-of-bounds write in LECP CBOR Recording
Summary: CVE-2026-78161 libwebsockets: libwebsockets: Out-of-bounds write in LECP CBOR...
Keywords:
Status: NEW
Alias: CVE-2026-78161
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-24 01:01 UTC by OSIDB Bzimport
Modified: 2026-08-24 12:05 UTC (History)
23 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-24 01:01:33 UTC
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.


Note You need to log in before you can comment on or make changes to this bug.