Bug 2502836 (CVE-2026-63090) - CVE-2026-63090 ProFTPD: mod_sftp: heap buffer overflow via SFTP packet reassembly
Summary: CVE-2026-63090 ProFTPD: mod_sftp: heap buffer overflow via SFTP packet reasse...
Keywords:
Status: NEW
Alias: CVE-2026-63090
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2502963 2502964
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-20 15:03 UTC by OSIDB Bzimport
Modified: 2026-07-20 19:21 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-20 15:03:17 UTC
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.


Note You need to log in before you can comment on or make changes to this bug.