UBUNTU-CVE-2025-11679

Source
https://ubuntu.com/security/CVE-2025-11679
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-11679
Upstream
  • CVE-2025-11679
Withdrawn
2026-02-12T05:22:01Z
Published
2025-10-20T14:15:00Z
Modified
2026-02-12T06:33:14.335283Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Out-of-bounds Read in lwsupngemitnextline in warmcat libwebsockets allows, when the LWSWITHUPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.

References

Affected packages

Ubuntu:16.04:LTS
libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@1.7.1-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.2.2-1
1.6.0-3
1.6.0-4
1.6.0-5
1.6.1-1
1.7.0-1ubuntu1
1.7.0-2
1.7.1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.7.1-1",
            "binary_name": "libwebsockets-dev"
        },
        {
            "binary_version": "1.7.1-1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "1.7.1-1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "1.7.1-1",
            "binary_name": "libwebsockets7"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json"
Ubuntu:18.04:LTS
libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@2.0.3-3build1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.3-3
2.0.3-3build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.0.3-3build1",
            "binary_name": "libwebsockets-dev"
        },
        {
            "binary_version": "2.0.3-3build1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "2.0.3-3build1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "2.0.3-3build1",
            "binary_name": "libwebsockets8"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json"
Ubuntu:20.04:LTS
libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@3.2.1-3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.3-3build1
3.*
3.2.1-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.2.1-3",
            "binary_name": "libwebsockets-dev"
        },
        {
            "binary_version": "3.2.1-3",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "3.2.1-3",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "3.2.1-3",
            "binary_name": "libwebsockets15"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json"
Ubuntu:22.04:LTS
libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@4.0.20-2ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.0.20-2
4.0.20-2ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.0.20-2ubuntu1",
            "binary_name": "libwebsockets-dev"
        },
        {
            "binary_version": "4.0.20-2ubuntu1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "4.0.20-2ubuntu1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "4.0.20-2ubuntu1",
            "binary_name": "libwebsockets16"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json"
Ubuntu:24.04:LTS
libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@4.3.3-1.1build3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.3.2-4
4.3.3-1
4.3.3-1.1build1
4.3.3-1.1build2
4.3.3-1.1build3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets-dev"
        },
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets-evlib-ev"
        },
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets-evlib-glib"
        },
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets-evlib-uv"
        },
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "4.3.3-1.1build3",
            "binary_name": "libwebsockets19t64"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json"
Ubuntu:25.10
libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@4.3.5-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.3.5-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets-dev"
        },
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets-evlib-ev"
        },
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets-evlib-glib"
        },
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets-evlib-uv"
        },
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "4.3.5-1",
            "binary_name": "libwebsockets19t64"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-11679.json"