CVE-2025-11678: Stack-based Buffer Overflow in libwebsockets DNS response parsing

Published Oct 20, 2025
·
Updated

Stack-based Buffer Overflow in lwsadnsparselabel in warmcat libwebsockets allows, when the LWSWITHSYSASYNCDNS flag is enabled during compilation, to overflow the labelstack, when the attacker is able to sniff a DNS request in order to craft a response with a matching id containing a label longer than the maximum.

Affected Software

1 affected component
libwebsockets

Remediation

Information

Update the library to its latest stable release, if not possible backport the fix commit 2bb9598562b37c942ba5b04bcde3f7fdf66a9d3a

Event History

Oct 20, 2025
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·05:24 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-11678?

CVE-2025-11678 is classified as a high severity vulnerability due to its potential for causing stack-based buffer overflow.

2

How do I fix CVE-2025-11678?

To fix CVE-2025-11678, disable the LWS_WITH_SYS_ASYNC_DNS flag during compilation or update to a patched version of warmcat libwebsockets.

3

What causes CVE-2025-11678?

CVE-2025-11678 is caused by a stack-based buffer overflow in the lws_adns_parse_label function when processing crafted DNS responses.

4

Which versions of warmcat libwebsockets are affected by CVE-2025-11678?

CVE-2025-11678 affects versions of warmcat libwebsockets that have the LWS_WITH_SYS_ASYNC_DNS flag enabled during compilation.

5

Can CVE-2025-11678 lead to remote code execution?

Yes, CVE-2025-11678 can potentially lead to remote code execution allowing attackers to compromise affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203