Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11679

Опубликовано: 20 окт. 2025
Источник: redhat
CVSS3: 3.1

Описание

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.

An out of bounds read has been discovered in libwebsockets. The issue is caused by the lws_upng_emit_next_line function, specifically in the branch when uf->padded is true, in the loop where it reads from the sliding window, ibp is incremented but never reset, making it possible to read past the buffer, and if the input file is big enough, reading past the currently mapped heap memory causing a crash.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1libwebsocketsFix deferred
Red Hat OpenStack Platform 16.2libwebsocketsFix deferred
Red Hat OpenStack Platform 17.1libwebsocketsFix deferred
Red Hat Service Interconnect 2libwebsocketsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2405115libwebsockets: Out-of-bounds Read in libwebsockets PNG parsing

3.1 Low

CVSS3

Связанные уязвимости

ubuntu
10 месяцев назад

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.

nvd
10 месяцев назад

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.

debian
10 месяцев назад

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets ...

github
10 месяцев назад

Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big height dimension.

3.1 Low

CVSS3