USN-8024-1

Source
https://ubuntu.com/security/notices/USN-8024-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8024-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8024-1
Upstream
Related
Published
2026-02-11T12:58:26Z
Modified
2026-04-27T18:36:50.452678Z
Summary
libwebsockets vulnerabilities
Details

Raffaele Bova discovered that Libwebsockets incorrectly handled memory when the upgrade header is not valid in the WebSocket server. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-11677)

Raffaele Bova discovered that Libwebsockets did not properly check the size of the destination buffer in the async-dns component. An attacker could possibly use this issue to cause applications to crash, leading to a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-11678)

References

Affected packages

Ubuntu:Pro:20.04:LTS / libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@3.2.1-3ubuntu0.1~esm1?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.1-3ubuntu0.1~esm1

Affected versions

2.*
2.0.3-3build1
3.*
3.2.1-3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.2.1-3ubuntu0.1~esm1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "3.2.1-3ubuntu0.1~esm1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "3.2.1-3ubuntu0.1~esm1",
            "binary_name": "libwebsockets15"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8024-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-11677",
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}

Ubuntu:22.04:LTS / libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@4.0.20-2ubuntu1.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.20-2ubuntu1.1

Affected versions

4.*
4.0.20-2
4.0.20-2ubuntu1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "4.0.20-2ubuntu1.1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "4.0.20-2ubuntu1.1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "4.0.20-2ubuntu1.1",
            "binary_name": "libwebsockets16"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8024-1.json"
cves_map
{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-11677",
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-11678",
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}

Ubuntu:Pro:24.04:LTS / libwebsockets

Package

Name
libwebsockets
Purl
pkg:deb/ubuntu/libwebsockets@4.3.3-1.1ubuntu0.1~esm1?arch=source&distro=esm-apps/noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.3-1.1ubuntu0.1~esm1

Affected versions

4.*
4.3.2-4
4.3.3-1
4.3.3-1.1build1
4.3.3-1.1build2
4.3.3-1.1build3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "4.3.3-1.1ubuntu0.1~esm1",
            "binary_name": "libwebsockets-evlib-ev"
        },
        {
            "binary_version": "4.3.3-1.1ubuntu0.1~esm1",
            "binary_name": "libwebsockets-evlib-glib"
        },
        {
            "binary_version": "4.3.3-1.1ubuntu0.1~esm1",
            "binary_name": "libwebsockets-evlib-uv"
        },
        {
            "binary_version": "4.3.3-1.1ubuntu0.1~esm1",
            "binary_name": "libwebsockets-test-server"
        },
        {
            "binary_version": "4.3.3-1.1ubuntu0.1~esm1",
            "binary_name": "libwebsockets-test-server-common"
        },
        {
            "binary_version": "4.3.3-1.1ubuntu0.1~esm1",
            "binary_name": "libwebsockets19t64"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8024-1.json"
cves_map
{
    "ecosystem": "Ubuntu:Pro:24.04:LTS",
    "cves": [
        {
            "id": "CVE-2025-11677",
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        },
        {
            "id": "CVE-2025-11678",
            "severity": [
                {
                    "type": "CVSS_V4",
                    "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}