UBUNTU-CVE-2025-11677
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-11677
UBUNTU-CVE-2025-11677
Summary:
Details: Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
References: https://ubuntu.com/security/CVE-2025-11677, https://www.cve.org/CVERecord?id=CVE-2025-11677, https://libwebsockets.org/git/libwebsockets/commit?id=2f082ec31261f556969160143ba94875d783971a, https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-11677, https://ubuntu.com/security/notices/USN-8024-1
Affected packages
Package
Name: libwebsockets
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
