Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11677

Опубликовано: 20 окт. 2025
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.

A use after free flaw has been discovered in the WebSocket server implementation of libwebsockets. The issue is caused by the lws_handshake_protocol function, specifically when the upgrade header is not valid, the function calls lws_http_transaction_completed, which frees some of the data in the wsi structure, then it calls user_callback_handle_rxflow passing the uppointer and uses it on following strcasecmp calls.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1libwebsocketsFix deferred
Red Hat OpenStack Platform 16.2libwebsocketsFix deferred
Red Hat OpenStack Platform 17.1libwebsocketsFix deferred
Red Hat Service Interconnect 2libwebsocketsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2405127libwebsockets: Use After Free in libwebsockets WebSocket server

EPSS

Процентиль: 31%
0.00377
Низкий

3.7 Low

CVSS3

Связанные уязвимости

ubuntu
10 месяцев назад

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.

nvd
10 месяцев назад

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.

debian
10 месяцев назад

Use After Free in WebSocket server implementation in lws_handshake_ser ...

github
10 месяцев назад

Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callback function that handles LWS_CALLBACK_HTTP_CONFIRM_UPGRADE, to achieve denial of service.

EPSS

Процентиль: 31%
0.00377
Низкий

3.7 Low

CVSS3