Back

HIGH

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library

Published May 16, 2025

Description

FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.

The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.

Affected products

Remediation

Vendor solution

Updating to version 2.4.5 of the included fcgi2 library and rebuilding the Perl module will protect against the vulnerability.

We also recommend limiting potential remote access to the FastCGI socket by declaring it as a UNIX socket.

Red Hat statement

This vulnerability is Important rather than just a Moderate flaw because it stems from an integer overflow in the allocation size calculation during parameter parsing in the FastCGI implementation. When the application processes incoming FastCGI parameters, it calculates the total size of memory to allocate by adding the name and value lengths along with two additional bytes. On 32-bit systems, this arithmetic operation can wrap around (due to the limited 32-bit size of size_t), leading to a significantly smaller allocation than intended. However, subsequent calls to FCGX_GetStr use the original (large) lengths provided by the attacker and write far beyond the allocated memory region (heap overflow). Unlike a moderate vulnerability (e.g., memory leak or a simple read out-of-bounds), this heap overflow directly allows an attacker to overwrite adjacent memory in the heap in a controlled way, potentially leading to arbitrary code execution, data corruption, or privilege escalation.

Red Hat mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published May 16, 2025
Updated Sep 5, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated May 16, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 16, 2025
ENISA EUVD
Assigner CPANSec
Published May 16, 2025
Updated Sep 5, 2025
Exploited since n/a
EUVD-2025-15438