Skip to content
Rota Nacional

Cyber ·

USN-8893-1: buffer overflow flaws in libwebsockets

Ubuntu Security notice on two libwebsockets flaws, one in HTTP/2 (HPACK) header processing and one in CBOR processing. Both can cause writes past the end of an allocated buffer and, in principle, arbitrary code execution.

Notice USN-8893-1, published on October 7, 2026 through the Ubuntu Security feed, describes two vulnerabilities in the libwebsockets library. The first, CVE-2026-19773, occurs because the library does not properly validate user-supplied data when parsing HTTP/2 HPACK path headers. This can result in a write past the end of an allocated buffer, and an attacker could possibly exploit it to run arbitrary code. The second, CVE-2026-78161, occurs because CBOR writes are not handled correctly in the LECP parser. It can also lead to a write past the end of an allocated buffer, with a possible process crash or arbitrary code execution. The text states that it is an automatic translation of the feed content, and the original notice is on the Ubuntu security notices page. To check whether your system is affected, consult that notice, identify the installed libwebsockets version, and compare it with the fixed versions listed by your distribution's vendor.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free