Notice USN-8893-1, published on October 7, 2026 through the Ubuntu Security feed, describes two vulnerabilities in the libwebsockets library. The first, CVE-2026-19773, occurs because the library does not properly validate user-supplied data when parsing HTTP/2 HPACK path headers. This can result in a write past the end of an allocated buffer, and an attacker could possibly exploit it to run arbitrary code. The second, CVE-2026-78161, occurs because CBOR writes are not handled correctly in the LECP parser. It can also lead to a write past the end of an allocated buffer, with a possible process crash or arbitrary code execution. The text states that it is an automatic translation of the feed content, and the original notice is on the Ubuntu security notices page. To check whether your system is affected, consult that notice, identify the installed libwebsockets version, and compare it with the fixed versions listed by your distribution's vendor.
Cyber ·
USN-8893-1: buffer overflow flaws in libwebsockets
Ubuntu Security notice on two libwebsockets flaws, one in HTTP/2 (HPACK) header processing and one in CBOR processing. Both can cause writes past the end of an allocated buffer and, in principle, arbitrary code execution.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.