CVE-2026-63090

NameCVE-2026-63090
DescriptionProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
proftpd-dfsg (PTS)bullseye1.3.7a+dfsg-12+deb11u2vulnerable
bullseye (security)1.3.7a+dfsg-12+deb11u5vulnerable
bookworm1.3.8+dfsg-4+deb12u5vulnerable
bookworm (security)1.3.8+dfsg-4+deb12u4vulnerable
trixie1.3.8.c+dfsg-4+deb13u2vulnerable
forky, sid1.3.9c~dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
proftpd-dfsgsource(unstable)1.3.9c~dfsg-1

Notes

https://github.com/proftpd/proftpd/issues/2190
Fixed by: https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b (v1.3.9c)

Search for package or bug name: Reporting problems