Logo
vulnerabilityCVE-2025-11678
Name
CVE-2025-11678
Source
NVD ( link)Debian ( link)
Description
Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libwebsockets
Patched

Vulnerability Ratings#


7.5
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
4.2.2
Not Affected
yocto
master
4.5.8
Not Affected

Resolved with patches#


libwebsockets (yocto:scarthgap)

#
Title
Author
Resolve
1
NN-2025-0103: ADNS crafted response overflow
Hugo SIMELIERE <hsimeliere.opensource@witekio.com>
CVE-2025-11678