ELA-1538-1 libfcgi security update

heap-based buffer overflow

2025-10-13
Packagelibfcgi
Version2.4.0-8.4+deb9u1 (stretch), 2.4.0-10+deb10u1 (buster)
Related CVEs CVE-2025-23016


An issue has been found in libfcgi, a FastCGI bridge from CGI. The issue is related to an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket.



For Debian 10 buster, these problems have been fixed in version 2.4.0-10+deb10u1.

For Debian 9 stretch, these problems have been fixed in version 2.4.0-8.4+deb9u1.

We recommend that you upgrade your libfcgi packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.