Description
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.
Problem types
Integer Overflow or Wraparound
Product status
0:3.0.5-10.el10_1.1 (rpm) before *
0:3.0.3-36.el8_10.3 (rpm) before *
0:3.0.5-6.el9_7.2 (rpm) before *
Timeline
| 2025-12-08: | Reported to Red Hat. |
| 2026-01-14: | Made public. |
Credits
Red Hat would like to thank Sankin Nikita Alexeevich for reporting this issue.
References
access.redhat.com/errata/RHSA-2026:0605 (RHSA-2026:0605)
access.redhat.com/errata/RHSA-2026:0606 (RHSA-2026:0606)
access.redhat.com/errata/RHSA-2026:0608 (RHSA-2026:0608)
access.redhat.com/security/cve/CVE-2025-14242
bugzilla.redhat.com/show_bug.cgi?id=2419826 (RHBZ#2419826)