Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Resolve CVE-2025-14242. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-67442bdd84 2026-01-23 00:54:29.972515+00:00 -------------------------------------------------------------------------------- Name : vsftpd Product : Fedora 43 Version : 3.0.5 Release : 14.fc43 URL : https://security.appspot.com/vsftpd.html Summary : Very Secure Ftp Daemon Description : vsftpd is a Very Secure FTP daemon. It was written completely from scratch. -------------------------------------------------------------------------------- Update Information: Resolve CVE-2025-14242 -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 14 2026 Tomas Korbar - 3.0.5-14 - Resolve CVE-2025-14242 * Thu Dec 18 2025 Fedor Vorobev - 3.0.5-13 - Add a tmpfiles.d config. (image mode support) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-67442bdd84' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Moderate: vsftpd security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0606", "synopsis": "Moderate: vsftpd security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vsftpd.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The vsftpd packages include a Very Secure File Transfer Protocol (FTP) daemon, which is used to serve files over a network.\n\nSecurity Fix(es):\n\n* vsftpd: vsftpd: Denial of service via integer overflow in ls command parameter parsing (CVE-2025-14242)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2419826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2419826", "description": ""}], "cves": [{"name": "CVE-2025-14242", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-14242", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-17T09:07:37.776055Z", "rpms": {"Rocky Linux 10": {"nvras": ["vsftpd-debugsource-0:3.0.5-10.el10_1.1.ppc64le.rpm", "vsftpd-debugsource-0:3.0.5-10.el10_1.1.aarch64.rpm", "vsftpd-debuginfo-0:3.0.5-10.el10_1.1.aarch64.rpm", "vsftpd-debuginfo-0:3.0.5-10.el10_1.1.x86_64.rpm", "vsftpd-debugsource-0:3.0.5-10.el10_1.1.x86_64.rpm", "vsftpd-0:3.0.5-10.el10_1.1.x86_64.rpm", "vsftpd-0:3.0.5-10.el10_1.1.src.rpm", "vsftpd-debuginfo-0:3.0.5-10.el10_1.1.s390x.rpm", "vsftpd-0:3.0.5-10.el10_1.1.ppc64le.rpm", "vsftpd-debugsource-0:3.0.5-10.el10_1.1.s390x.rpm", "vsftpd-0:3.0.5-10.el10_1.1.s390x.rpm", "vsftpd-0:3.0.5-10.el10_1.1.aarch64.rpm","vsftpd-debuginfo-0:3.0.5-10.el10_1.1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate vsftpd security update for Rocky Linux addressing denial of service exploitation.. vsftpd security update, Rocky Linux advisory, denial of service fix, CVE-2025-14242, security measures. . Severity: moderate. LinuxSecurity.com Team
Moderate: vsftpd security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0605", "synopsis": "Moderate: vsftpd security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vsftpd.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The vsftpd packages include a Very Secure File Transfer Protocol (FTP) daemon, which is used to serve files over a network.\n\nSecurity Fix(es):\n\n* vsftpd: vsftpd: Denial of service via integer overflow in ls command parameter parsing (CVE-2025-14242)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2419826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2419826", "description": ""}], "cves": [{"name": "CVE-2025-14242", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-14242", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-17T09:05:06.143150Z", "rpms": {"Rocky Linux 9": {"nvras": ["vsftpd-0:3.0.5-6.el9_7.2.aarch64.rpm", "vsftpd-0:3.0.5-6.el9_7.2.ppc64le.rpm", "vsftpd-0:3.0.5-6.el9_7.2.s390x.rpm", "vsftpd-0:3.0.5-6.el9_7.2.src.rpm", "vsftpd-0:3.0.5-6.el9_7.2.x86_64.rpm", "vsftpd-debuginfo-0:3.0.5-6.el9_7.2.aarch64.rpm", "vsftpd-debuginfo-0:3.0.5-6.el9_7.2.ppc64le.rpm", "vsftpd-debuginfo-0:3.0.5-6.el9_7.2.s390x.rpm", "vsftpd-debuginfo-0:3.0.5-6.el9_7.2.x86_64.rpm", "vsftpd-debugsource-0:3.0.5-6.el9_7.2.aarch64.rpm", "vsftpd-debugsource-0:3.0.5-6.el9_7.2.ppc64le.rpm", "vsftpd-debugsource-0:3.0.5-6.el9_7.2.s390x.rpm", "vsftpd-debugsource-0:3.0.5-6.el9_7.2.x86_64.rpm"]}}, "rebootSuggested":false, "buildReferences": []}. Moderate vsftpd security update for Rocky Linux fixes DoS via integer overflow. Essential patch available now.. vsftpd security update, Rocky Linux advisory, denial of service, CVE-2025-14242. . Severity: moderate. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0606 http://linux.oracle.com/errata/ELSA-2026-0606.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: vsftpd-3.0.5-10.el10_1.1.x86_64.rpm aarch64: vsftpd-3.0.5-10.el10_1.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/vsftpd-3.0.5-10.el10_1.1.src.rpm Related CVEs: CVE-2025-14242 Description of changes: [3.0.5-10.1] - Fix CVE-2025-14242 - Resolves: RHEL-134158 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0605 http://linux.oracle.com/errata/ELSA-2026-0605.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vsftpd-3.0.5-6.el9_7.2.x86_64.rpm aarch64: vsftpd-3.0.5-6.el9_7.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vsftpd-3.0.5-6.el9_7.2.src.rpm Related CVEs: CVE-2025-14242 Description of changes: [3.0.5-6.2] - Rebuild to test with proper configuration - Related: RHEL-134169 [3.0.5-6.1] - Fix CVE-2025-14242 - Resolves: RHEL-134169 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0608 http://linux.oracle.com/errata/ELSA-2026-0608.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: vsftpd-3.0.3-36.el8_10.3.x86_64.rpm aarch64: vsftpd-3.0.3-36.el8_10.3.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/vsftpd-3.0.3-36.el8_10.3.src.rpm Related CVEs: CVE-2025-14242 Description of changes: [3.0.3-36.3] - Rebuild to test with proper configuration - Related: RHEL-134160 [3.0.3-36.2] - Rebuild to test with proper configuration - Related: RHEL-134160 [3.0.3-36.1] - Fix CVE-2025-14242 - Resolves: RHEL-134160 _______________________________________________ El-errata mailing list
Moderate: vsftpd security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0608", "synopsis": "Moderate: vsftpd security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vsftpd.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The vsftpd packages include a Very Secure File Transfer Protocol (FTP) daemon, which is used to serve files over a network.\n\nSecurity Fix(es):\n\n* vsftpd: vsftpd: Denial of service via integer overflow in ls command parameter parsing (CVE-2025-14242)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2419826", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2419826", "description": ""}], "cves": [{"name": "CVE-2025-14242", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-14242", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-01-15T09:11:45.290734Z", "rpms": {"Rocky Linux 8": {"nvras": ["vsftpd-0:3.0.3-36.el8_10.3.aarch64.rpm", "vsftpd-0:3.0.3-36.el8_10.3.src.rpm", "vsftpd-0:3.0.3-36.el8_10.3.x86_64.rpm", "vsftpd-debuginfo-0:3.0.3-36.el8_10.3.aarch64.rpm", "vsftpd-debuginfo-0:3.0.3-36.el8_10.3.x86_64.rpm", "vsftpd-debugsource-0:3.0.3-36.el8_10.3.aarch64.rpm", "vsftpd-debugsource-0:3.0.3-36.el8_10.3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate security update for vsftpd on Rocky Linux addresses a denial of service risk. Prompt patching is advised.. Rocky Linux security update vsftpd denial of service CVE-2025-14242. . Severity: moderate. LinuxSecurity.com Team
vsftpd could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-6379-1 September 18, 2023 vsftpd vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: vsftpd could allow unintended access to network services. Software Description: - vsftpd: FTP server written for security Details: It was discovered that vsftpd was vulnerable to the ALPACA TLS protocol content confusion attack. A remote attacker could possibly use this issue to redirect traffic from one subdomain to another. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: vsftpd 3.0.5-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6379-1 CVE-2021-3618 Package Information: https://launchpad.net/ubuntu/+source/vsftpd/3.0.5-0ubuntu0.20.04.1 . Ubuntu Security Announcement USN-6380-1 details a severe vsftpd vulnerability impacting Ubuntu 22.04 LTS.. vsftpd access, Ubuntu 20.04, security notice, critical update, remote attack. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.