A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade vsftpd | Jan 20, 2026 | Jan 14, 2026 |
| Amazon Linux Ami 2 | — | Upgrade vsftpd-sysvinitUpgrade vsftpd-debuginfoUpgrade vsftpd | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade vsftpd-debugsourceUpgrade vsftpd-debuginfoUpgrade vsftpd | Feb 20, 2026 | Jan 14, 2026 |
| Oracle_linux | — | Upgrade vsftpd | Jan 19, 2026 | Jan 14, 2026 |
| Redhat_linux | — | No solution existsUpgrade vsftpd-debugsourceUpgrade vsftpdUpgrade vsftpd-debuginfo | Jan 15, 2026 | Jan 14, 2026 |
| Rocky_linux | — | Upgrade vsftpd-debugsourceUpgrade vsftpdUpgrade vsftpd-debuginfo | Jan 16, 2026 | Jan 15, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub