yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-23016
Component Overview
Vulnerability Overview
Name
CVE-2025-23016
Source
NVD (
link
)
Debian (
link
)
Description
FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
CWEs
CWE-190
Published Date
Jan 10, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
fcgi
Patched
Vulnerability Ratings
#
9.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libfcgi
buildroot
2025.02.x
2.4.7
Not Affected
libfcgi
buildroot
master
2.4.7
Not Affected
fcgi
yocto
master
2.4.7
Not Affected
fcgi
yocto
scarthgap
2.4.2
Patched
Resolved with patches
#
fcgi (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix size_t overflow in Malloc() argument in ReadParams()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2025-23016
2
Update fcgiapp.c
Pycatchown <39068868+Pycatchown@users.noreply.github.com>
CVE-2025-23016
fcgi (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix size_t overflow in Malloc() argument in ReadParams()
=?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
CVE-2025-23016
2
Update fcgiapp.c
Pycatchown <39068868+Pycatchown@users.noreply.github.com>
CVE-2025-23016