Source: libre
Version: 2.0.1-3
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://github.com/baresip/re/pull/1584
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for libre.

CVE-2026-50161[0]:
| libre is a generic library for real-time communications with
| asynchronous input and output support. Prior to 4.8.1, the
| websock_decode() function in src/websock/websock.c contains an
| integer overflow when validating a masked WebSocket frame that uses
| the 64-bit extended length encoding. The expression 4 + hdr->len can
| wrap when hdr->len is close to UINT64_MAX, causing the
| mbuf_get_left() bounds check to pass. The subsequent XOR unmasking
| loop then writes beyond the heap buffer. Applications using
| websock_accept() or websock_accept_proto() to implement a WebSocket
| server are affected, and exploitation can cause attacker-controlled
| heap corruption or denial of service after the HTTP WebSocket
| upgrade handshake. This issue is fixed in version 4.8.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-50161
    https://www.cve.org/CVERecord?id=CVE-2026-50161
[1] https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h
[2] https://github.com/baresip/re/pull/1584
[3] 
https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8

Regards,
Salvatore

Reply via email to