<Vulnerability name="CVE-2026-78161">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-24T00:45:08</PublicDate>
    <Bugzilla id="2521703" url="https://bugzilla.redhat.com/show_bug.cgi?id=2521703" xml:lang="en:us">
libwebsockets: libwebsockets: Out-of-bounds write in LECP CBOR Recording
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-787</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply a patch to resolve this issue.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in warmcat libwebsockets. A remote attacker could exploit an out-of-bounds write vulnerability in the LECP CBOR Recording component, specifically within the `report_raw_cbor` function. This could lead to information disclosure, data corruption, or denial of service.
    </Details>
    <Statement xml:lang="en:us">
A vulnerability was found in libwebsockets 4.5.0 only. This vulnerability in libwebsockets, an out-of-bounds write in the LECP CBOR Recording component, does not affect Red Hat products. The vulnerable code is not present in the versions of libwebsockets shipped with Red Hat offerings.
    </Statement>
    <PackageState cpe="cpe:/a:redhat:amq_interconnect:1">
        <ProductName>A-MQ Interconnect 1</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>libwebsockets</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:16.2">
        <ProductName>Red Hat OpenStack Platform 16.2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>libwebsockets</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:17.1">
        <ProductName>Red Hat OpenStack Platform 17.1</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>libwebsockets</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:satellite:6">
        <ProductName>Red Hat Satellite 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>libwebsockets</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:service_interconnect:2">
        <ProductName>Red Hat Service Interconnect 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>libwebsockets</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-78161
https://nvd.nist.gov/vuln/detail/CVE-2026-78161
https://github.com/biniamf/pocs/blob/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write/poc_lecp_cbor_pos_oob.c
https://github.com/biniamf/pocs/tree/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write
https://github.com/warmcat/libwebsockets/
https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054
https://vuldb.com/cve/CVE-2026-78161
https://vuldb.com/submit/883225
https://vuldb.com/vuln/394543
https://vuldb.com/vuln/394543/cti
    </References>
</Vulnerability>