Source: libre Version: 2.0.1-3 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://github.com/baresip/re/pull/1584 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libre. CVE-2026-50161[0]: | libre is a generic library for real-time communications with | asynchronous input and output support. Prior to 4.8.1, the | websock_decode() function in src/websock/websock.c contains an | integer overflow when validating a masked WebSocket frame that uses | the 64-bit extended length encoding. The expression 4 + hdr->len can | wrap when hdr->len is close to UINT64_MAX, causing the | mbuf_get_left() bounds check to pass. The subsequent XOR unmasking | loop then writes beyond the heap buffer. Applications using | websock_accept() or websock_accept_proto() to implement a WebSocket | server are affected, and exploitation can cause attacker-controlled | heap corruption or denial of service after the HTTP WebSocket | upgrade handshake. This issue is fixed in version 4.8.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-50161 https://www.cve.org/CVERecord?id=CVE-2026-50161 [1] https://github.com/baresip/re/security/advisories/GHSA-hvxv-v2gp-v93h [2] https://github.com/baresip/re/pull/1584 [3] https://github.com/baresip/re/commit/718b92615c7963670d26c1a2b246968b58d782e8 Regards, Salvatore

