CVE-2025-11678

EUVD-2025-35057
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Debian logo
Debian Releases
Debian Product
Codename
libwebsockets
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
4.0.20-2+deb11u1
fixed
forky
4.3.5-3
fixed
sid
4.3.5-3
fixed
trixie
4.3.5-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libwebsockets
bionic
not-affected
focal
not-affected
jammy
Fixed 4.0.20-2ubuntu1.1
released
noble
Fixed 4.3.3-1.1ubuntu0.1~esm1
released
plucky
ignored
questing
needed
xenial
not-affected