Version in base suite: 4.3.5-1+deb13u2 Base version: libwebsockets_4.3.5-1+deb13u2 Target version: libwebsockets_4.3.5-1+deb13u3 Base file: /srv/ftp-master.debian.org/ftp/pool/main/libw/libwebsockets/libwebsockets_4.3.5-1+deb13u2.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/libw/libwebsockets/libwebsockets_4.3.5-1+deb13u3.dsc changelog | 6 ++++++ patches/CVE-2026-19773.patch | 17 +++++++++++++++++ patches/series | 1 + 3 files changed, 24 insertions(+) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp6xbzsh8d/libwebsockets_4.3.5-1+deb13u2.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp6xbzsh8d/libwebsockets_4.3.5-1+deb13u3.dsc: no acceptable signature found diff -Nru libwebsockets-4.3.5/debian/changelog libwebsockets-4.3.5/debian/changelog --- libwebsockets-4.3.5/debian/changelog 2026-08-27 16:56:33.000000000 +0000 +++ libwebsockets-4.3.5/debian/changelog 2026-09-27 20:41:54.000000000 +0000 @@ -1,3 +1,9 @@ +libwebsockets (4.3.5-1+deb13u3) trixie-security; urgency=medium + + * CVE-2026-19773 + + -- Moritz Mühlenhoff Sun, 27 Sep 2026 22:41:54 +0200 + libwebsockets (4.3.5-1+deb13u2) trixie; urgency=medium * Backport upstream security fix for CVE-2026-10650: resource consumption diff -Nru libwebsockets-4.3.5/debian/patches/CVE-2026-19773.patch libwebsockets-4.3.5/debian/patches/CVE-2026-19773.patch --- libwebsockets-4.3.5/debian/patches/CVE-2026-19773.patch 1970-01-01 00:00:00.000000000 +0000 +++ libwebsockets-4.3.5/debian/patches/CVE-2026-19773.patch 2026-09-27 20:41:50.000000000 +0000 @@ -0,0 +1,17 @@ +From 824151862f37bc72f46d9a3e01d5b9408d313a0b Mon Sep 17 00:00:00 2001 +From: Andy Green +Date: Fri, 3 Jul 2026 18:43:25 +0100 +Subject: [PATCH] zdi-can-31036: h2 bounds check on server + +--- libwebsockets-4.3.5.orig/lib/roles/h2/hpack.c ++++ libwebsockets-4.3.5/lib/roles/h2/hpack.c +@@ -274,6 +274,9 @@ static int lws_frag_append(struct lws *w + { + struct allocated_headers *ah = wsi->http.ah; + ++ if ((unsigned int)ah->pos >= wsi->a.context->max_http_header_data) ++ return 1; ++ + ah->data[ah->pos++] = (char)c; + ah->frags[ah->nfrag].len++; + diff -Nru libwebsockets-4.3.5/debian/patches/series libwebsockets-4.3.5/debian/patches/series --- libwebsockets-4.3.5/debian/patches/series 2026-08-27 16:56:17.000000000 +0000 +++ libwebsockets-4.3.5/debian/patches/series 2026-09-27 20:41:40.000000000 +0000 @@ -2,3 +2,4 @@ CVE-2025-11678.patch CVE-2026-10650.patch CVE-2026-78161.patch +CVE-2026-19773.patch