Logo
vulnerabilityCVE-2026-63090
Name
CVE-2026-63090
Source
NVD ( link)Debian ( link)
Description
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
proftpd
Exploitable

Vulnerability Ratings#


8.7
CVSSv4
8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.8d
Exploitable
yocto
kirkstone
1.3.7c
Exploitable
yocto
master
1.3.9c
Not Affected
yocto
scarthgap
1.3.7f
Exploitable