Logo
vulnerabilityCVE-2025-11677
Name
CVE-2025-11677
Source
NVD ( link)Debian ( link)
Description
Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libwebsockets
Patched

Vulnerability Ratings#


6.3
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
4.2.2
Not Affected
yocto
master
4.5.8
Not Affected

Resolved with patches#


libwebsockets (yocto:scarthgap)

#
Title
Author
Resolve
1
NN-2025-0102: UAF depending on upgrade allowed
Hugo SIMELIERE <hsimeliere.opensource@witekio.com>
CVE-2025-11677