CVE-2025-14242
vsftpd vulnerability analysis and mitigation

Overview

CVE-2025-14242 is a denial-of-service vulnerability in vsftpd caused by an integer overflow in the ls command parameter parsing. A remote, authenticated attacker can trigger the flaw by sending a crafted STAT command with a specific byte sequence, causing the daemon to crash. The vulnerability was reported on December 8, 2025, and publicly disclosed on January 14, 2026. It affects vsftpd as shipped in Red Hat Enterprise Linux 8, 9, and 10 (and their extended support variants), and is specific to a Red Hat-applied patch adding square bracket support to the ls command. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in the parameter parsing logic of vsftpd's ls command implementation. Specifically, the flaw resides in a Red Hat-specific patch that added square bracket ([...]) glob support to the ls command — the vulnerability does not exist in upstream vsftpd. An authenticated attacker sends a crafted FTP STAT command containing a particular byte sequence that triggers the integer overflow during parameter parsing, leading to a crash of the vsftpd process. The attack vector is network-based, requires low privileges (valid FTP credentials), and no user interaction (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation results in a denial-of-service condition, crashing the vsftpd daemon and disrupting FTP service availability for all users. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (CVSS A:H, C:N, I:N). The scope is limited to the affected vsftpd instance; lateral movement or data exfiltration are not directly enabled by this vulnerability (Red Hat CVE, RHSA-2026:0605).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-14242. The vulnerability requires valid FTP credentials, limiting the attacker pool to authenticated users. The EPSS score is approximately 0.165%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Red Hat CVE).

Exploitation steps

  1. Obtain FTP credentials: Acquire valid credentials for the target vsftpd server (e.g., through credential stuffing, phishing, or use of a low-privilege account).
  2. Connect to the FTP server: Establish an authenticated FTP session to the target running a vulnerable version of vsftpd on RHEL 8, 9, or 10.
  3. Craft a malicious STAT command: Send a STAT command with a specially crafted argument containing a specific byte sequence designed to trigger the integer overflow in the square-bracket glob parsing logic of the ls command parameter handler.
  4. Trigger the DoS: The crafted input causes an integer overflow during parameter parsing, crashing the vsftpd process and denying FTP service to all users (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • Logs: Unexpected vsftpd process crashes or restarts in /var/log/vsftpd.log or system journal (journalctl -u vsftpd); FTP session logs showing STAT commands with unusual or malformed arguments from a specific source IP.
  • Process: Sudden termination of the vsftpd process (visible via systemctl status vsftpd showing a failed state or core dump).
  • Network: Repeated FTP STAT commands with non-standard or binary-containing argument strings from the same authenticated client IP address.

Mitigation and workarounds

Red Hat released patched packages on January 14, 2026. Administrators should update to the following fixed versions:

Additional extended support updates were released in March 2026 for RHEL 8.2, 8.4, 8.6, 8.8, 9.0, 9.2, 9.4, and 9.6 variants. As a short-term workaround where patching is not immediately possible, restricting FTP access to trusted, authenticated users and monitoring for anomalous STAT commands can reduce exposure (Red Hat Bugzilla).

Community reactions

Red Hat Product Security rated this vulnerability as "Moderate" severity and coordinated patches across multiple RHEL versions simultaneously on the disclosure date. A Debian/Fedora community contributor (Salvatore Bonaccorso) confirmed via the Red Hat Bugzilla that the vulnerability is specific to the Red Hat-applied square bracket patch and does not affect upstream vsftpd, which was acknowledged by Red Hat's Tomas Korbar (Red Hat Bugzilla). Coverage was limited to standard vulnerability tracking outlets and Linux security advisory aggregators, with no significant broader media attention.

Additional resources


SourceThis report was generated using AI

Related vsftpd vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2011-2523CRITICAL9.8
  • vsftpd logovsftpd
  • vsftpd
NoYesNov 27, 2019
CVE-2021-30047HIGH7.5
  • vsftpd logovsftpd
  • vsftpd
NoNoAug 22, 2023
CVE-2021-3618HIGH7.4
  • Go logoGo
  • nginx:1.18::nginx-mod-stream
NoYesMar 23, 2022
CVE-2025-14242MEDIUM6.5
  • vsftpd logovsftpd
  • vsftpd
NoYesJan 14, 2026
CVE-2015-1419MEDIUM5
  • vsftpd logovsftpd
  • vsftpd
NoYesJan 28, 2015

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management