CVE-2025-23016

Publication date 10 January 2025

Last updated 6 May 2025


Ubuntu priority

FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

Status

Package Ubuntu Release Status
libfcgi 25.04 plucky
Fixed 2.4.2-2.1ubuntu0.25.04.1
24.10 oracular
Fixed 2.4.2-2.1ubuntu0.24.10.1
24.04 LTS noble
Fixed 2.4.2-2.1ubuntu0.24.04.1
22.04 LTS jammy
Fixed 2.4.2-2ubuntu0.1
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libfcgi

References

Related Ubuntu Security Notices (USN)

Other references