-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 03 Nov 2025 16:30:57 +0100 Source: libwebsockets Built-For-Profiles: noudeb Architecture: source Version: 4.0.20-2+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org> Changed-By: Utkarsh Gupta <utkarsh@debian.org> Closes: 1118746 1118747 Changes: libwebsockets (4.0.20-2+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the LTS team. * Add patch to fix CVE-2025-11677. (Closes: #1118747) - UAF depending on upgrade allowed. * Add patch to fix CVE-2025-11678. (Closes: #1118746) - ADNS crafted response overflow. Checksums-Sha1: 885e2d93f872dcf8e311599cf400bd7f6aeb59ff 2358 libwebsockets_4.0.20-2+deb11u1.dsc b3a010400038fd777bf127173527a1f2c43d5093 12342036 libwebsockets_4.0.20.orig.tar.gz 91a2ca4fb576f6b13bd5874fee6de4891e4ae9cb 20976 libwebsockets_4.0.20-2+deb11u1.debian.tar.xz de504c5e3aea14b4da9a726568c16e87f0f15e42 8518 libwebsockets_4.0.20-2+deb11u1_source.buildinfo Checksums-Sha256: c0c10249876a4cfd3389f51880248d74b82db97ebbb17f8cf6f70acc7bb34ac3 2358 libwebsockets_4.0.20-2+deb11u1.dsc a26d243f2642a9b810e7d91f1e66b149d1da978decdca58ce1c9218c454f397e 12342036 libwebsockets_4.0.20.orig.tar.gz 641e73b1cc823ff1a654957cad22a8cb3449473d145769c66b97eb76b4b0a857 20976 libwebsockets_4.0.20-2+deb11u1.debian.tar.xz de609c08f704b934722eb2d8363cb820382a0366f5310b1ccc98bfa3af44c46f 8518 libwebsockets_4.0.20-2+deb11u1_source.buildinfo Files: 3c2d3e73d3ddc6d67eceac989f056f01 2358 libs optional libwebsockets_4.0.20-2+deb11u1.dsc eb5f75a1a99546f7a564f9aa49835ba1 12342036 libs optional libwebsockets_4.0.20.orig.tar.gz fb914d8bb38c0a337f1f107421d58710 20976 libs optional libwebsockets_4.0.20-2+deb11u1.debian.tar.xz 1434575fd8637edab768e5dac19e78a1 8518 libs optional libwebsockets_4.0.20-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJHBAEBCgAxFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmkZrYETHHV0a2Fyc2hA ZGViaWFuLm9yZwAKCRCCPpZ2BsNLlvr+D/9ucfeUfU8SQmRWKombAj7mTQz5GRpC XCnlg27DzLvJ98f4WHdZJ9MIi0pLefLklZ8tBJ5Ds1zjNvTorhZp7oq+I3hsOuYB JL+oRPhImh2Y7qVO4dyKioOPPbTchEOhv4Wx5PwIulLDDIhQaHGY4eYoalVHXe2D W479JK4CSDorvoaMD7tmogRs3I5jZnsZzT1zMIgFW0DBqWtvJcqU1HpuF4ZIgq9z /CBWMYcQuXzXmAjcJ+7/95oHCGyVgStuNi+M3kdLN2jTNHT8necSs0Pt5TF3Star fd0JFVhtjQ4FpWIVNn9eQ4loVK6WPC8N0WF8Ebdpw8FpT2JhkfFOqSELrB2NC1Od ZU0u0uagylCvfoTVLYhfZ54txG3PQZzK/IrauGYJzhCUNUU8DAGv3ZkAXglMvZzq /bjqJE8ZwE+Xrruud2CuXu8JACTq+FqpvztawXF81emzbnK6I824K+lSEp9HmAVZ SRCBfANtpbSyH6A64p7quVc+rBs2KRmOMPbfMbEoO9jzx4C3JQJSWO3yhj6hF8bs dg581i4ZtQCfyjGvYQLsr00yPHQ4M0RuACLneMFIx8OOaVywg9qEAsOTdK/PAdZH L3A8vJ2YgJvw78wMABs61mWSkvF7woWfqidYWzEdUdSLMsx4pE5lXf1iES+fEzxc isOgN4Kt3h0RRQ== =EwZ6 -----END PGP SIGNATURE-----