
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14242 is a denial-of-service vulnerability in vsftpd caused by an integer overflow in the ls command parameter parsing. A remote, authenticated attacker can trigger the flaw by sending a crafted STAT command with a specific byte sequence, causing the daemon to crash. The vulnerability was reported on December 8, 2025, and publicly disclosed on January 14, 2026. It affects vsftpd as shipped in Red Hat Enterprise Linux 8, 9, and 10 (and their extended support variants), and is specific to a Red Hat-applied patch adding square bracket support to the ls command. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in the parameter parsing logic of vsftpd's ls command implementation. Specifically, the flaw resides in a Red Hat-specific patch that added square bracket ([...]) glob support to the ls command — the vulnerability does not exist in upstream vsftpd. An authenticated attacker sends a crafted FTP STAT command containing a particular byte sequence that triggers the integer overflow during parameter parsing, leading to a crash of the vsftpd process. The attack vector is network-based, requires low privileges (valid FTP credentials), and no user interaction (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation results in a denial-of-service condition, crashing the vsftpd daemon and disrupting FTP service availability for all users. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (CVSS A:H, C:N, I:N). The scope is limited to the affected vsftpd instance; lateral movement or data exfiltration are not directly enabled by this vulnerability (Red Hat CVE, RHSA-2026:0605).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-14242. The vulnerability requires valid FTP credentials, limiting the attacker pool to authenticated users. The EPSS score is approximately 0.165%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).
ls command parameter handler./var/log/vsftpd.log or system journal (journalctl -u vsftpd); FTP session logs showing STAT commands with unusual or malformed arguments from a specific source IP.vsftpd process (visible via systemctl status vsftpd showing a failed state or core dump).Red Hat released patched packages on January 14, 2026. Administrators should update to the following fixed versions:
vsftpd-3.0.3-36.el8_10.3 (via RHSA-2026:0608)vsftpd-3.0.5-6.el9_7.2 (via RHSA-2026:0605)vsftpd-3.0.5-10.el10_1.1 (via RHSA-2026:0606)Additional extended support updates were released in March 2026 for RHEL 8.2, 8.4, 8.6, 8.8, 9.0, 9.2, 9.4, and 9.6 variants. As a short-term workaround where patching is not immediately possible, restricting FTP access to trusted, authenticated users and monitoring for anomalous STAT commands can reduce exposure (Red Hat Bugzilla).
Red Hat Product Security rated this vulnerability as "Moderate" severity and coordinated patches across multiple RHEL versions simultaneously on the disclosure date. A Debian/Fedora community contributor (Salvatore Bonaccorso) confirmed via the Red Hat Bugzilla that the vulnerability is specific to the Red Hat-applied square bracket patch and does not affect upstream vsftpd, which was acknowledged by Red Hat's Tomas Korbar (Red Hat Bugzilla). Coverage was limited to standard vulnerability tracking outlets and Linux security advisory aggregators, with no significant broader media attention.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."