Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Fedora 42: Civetweb Critical DoS Issue FEDORA-2025-1056ea31ed

fedora
Calendar Grey October 8, 2025
Scroller Fedora
Learn about the critical Denial of Service issue in CivetWeb for Fedora 42 and how to apply the update efficiently.
civetweb-1.16, rhbz#240016

Summary

Civetweb is an easy to use, powerful, C (C/C++) embeddable web server

with optional CGI, SSL and Lua support.

CivetWeb can be used by developers as a library, to add web server

functionality to an existing application. It can also be used by end

users as a stand-alone web server running on a Windows or Linux PC.

It is available as single executable, no installation is required.

Update Information:

civetweb-1.16, rhbz#240016

Change Log

* Mon Sep 29 2025 Kaleb S. KEITHLEY - 1.16-10 - civetweb 1.16, rhbz#2400166

References


[ 1 ] Bug #2400166 - CVE-2025-9648 civetweb: Denial of Service in CivetWeb [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2400166

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1056ea31ed' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: civetweb
Product: Fedora 42
Version: 1.16
Release: 10.fc42
Summary: Embedded C/C++ web server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.