FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library
Published May 16, 2025
7.5
HIGHCVSS 3.1
EPSS 0.65%
Description
FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library.
The included FastCGI library is affected by CVE-2025-23016, causing an integer overflow (and resultant heap-based buffer overflow) via crafted nameLen or valueLen values in data to the IPC socket. This occurs in ReadParams in fcgiapp.c.
Affected products
-
- Version 0.44StatusaffectedConstraints<=0.82
- Version
No data.
Red Hat Enterprise Linux 10
perl-FCGI-1:0.82-13.1.el10_0
Fixed · RHSA-2025:8636
Red Hat Enterprise Linux 7 Extended Lifecycle Support
perl-FCGI-1:0.74-8.el7_9.1
Fixed · RHSA-2025:8625
Red Hat Enterprise Linux 8
perl-FCGI:0.78-8100020250529111022.491cfe3d
Fixed · RHSA-2025:8696
Red Hat Enterprise Linux 8.2 Advanced Update Support
perl-FCGI:0.78-8020020250607180124.89a48cc6
Fixed · RHSA-2025:8829
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
perl-FCGI:0.78-8040020250606192145.18ae627e
Fixed · RHSA-2025:8703
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
perl-FCGI:0.78-8060020250604201935.513b2a65
Fixed · RHSA-2025:8890
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
perl-FCGI:0.78-8060020250604201935.513b2a65
Fixed · RHSA-2025:8890
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
perl-FCGI:0.78-8060020250604201935.513b2a65
Fixed · RHSA-2025:8890
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
perl-FCGI:0.78-8080020250603232512.6ceb32a8
Fixed · RHSA-2025:8698
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
perl-FCGI:0.78-8080020250603232512.6ceb32a8
Fixed · RHSA-2025:8698
Red Hat Enterprise Linux 9
perl-FCGI-1:0.79-8.1.el9_6
Fixed · RHSA-2025:8635
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
perl-FCGI-1:0.79-8.el9_0.1
Fixed · RHSA-2025:8678
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
perl-FCGI-1:0.79-8.el9_2.1
Fixed · RHSA-2025:8697
Red Hat Enterprise Linux 9.4 Extended Update Support
perl-FCGI-1:0.79-8.el9_4.1
Fixed · RHSA-2025:8677
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | perl-FCGI-1:0.82-13.1.el10_0 | Fixed | RHSA-2025:8636 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | perl-FCGI-1:0.74-8.el7_9.1 | Fixed | RHSA-2025:8625 |
| Red Hat Enterprise Linux 8 | perl-FCGI:0.78-8100020250529111022.491cfe3d | Fixed | RHSA-2025:8696 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | perl-FCGI:0.78-8020020250607180124.89a48cc6 | Fixed | RHSA-2025:8829 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | perl-FCGI:0.78-8040020250606192145.18ae627e | Fixed | RHSA-2025:8703 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | perl-FCGI:0.78-8060020250604201935.513b2a65 | Fixed | RHSA-2025:8890 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | perl-FCGI:0.78-8060020250604201935.513b2a65 | Fixed | RHSA-2025:8890 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | perl-FCGI:0.78-8060020250604201935.513b2a65 | Fixed | RHSA-2025:8890 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | perl-FCGI:0.78-8080020250603232512.6ceb32a8 | Fixed | RHSA-2025:8698 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | perl-FCGI:0.78-8080020250603232512.6ceb32a8 | Fixed | RHSA-2025:8698 |
| Red Hat Enterprise Linux 9 | perl-FCGI-1:0.79-8.1.el9_6 | Fixed | RHSA-2025:8635 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | perl-FCGI-1:0.79-8.el9_0.1 | Fixed | RHSA-2025:8678 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | perl-FCGI-1:0.79-8.el9_2.1 | Fixed | RHSA-2025:8697 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | perl-FCGI-1:0.79-8.el9_4.1 | Fixed | RHSA-2025:8677 |
No package ranges for this CVE.
Remediation
Vendor solution
Updating to version 2.4.5 of the included fcgi2 library and rebuilding the Perl module will protect against the vulnerability.
We also recommend limiting potential remote access to the FastCGI socket by declaring it as a UNIX socket.
Red Hat statement
This vulnerability is Important rather than just a Moderate flaw because it stems from an integer overflow in the allocation size calculation during parameter parsing in the FastCGI implementation. When the application processes incoming FastCGI parameters, it calculates the total size of memory to allocate by adding the name and value lengths along with two additional bytes. On 32-bit systems, this arithmetic operation can wrap around (due to the limited 32-bit size of size_t), leading to a significantly smaller allocation than intended. However, subsequent calls to FCGX_GetStr use the original (large) lengths provided by the attacker and write far beyond the allocated memory region (heap overflow). Unlike a moderate vulnerability (e.g., memory leak or a simple read out-of-bounds), this heap overflow directly allows an attacker to overwrite adjacent memory in the heap in a controlled way, potentially leading to arbitrary code execution, data corruption, or privilege escalation.
Red Hat mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
References (11)
- http://www.openwall.com/lists/oss-security/2025/04/23/4 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-40907 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2366847 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15438 Advisory
- https://github.com/FastCGI-Archives/fcgi2/issues/67 issue-trackingExploitIssue Tracking
- https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5 patchRelease Notes
- https://github.com/perl-catalyst/FCGI/issues/14 issue-trackingExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-40907
- https://patch-diff.githubusercontent.com/raw/FastCGI-Archives/fcgi2/pull/74.patch patch
- https://www.cve.org/CVERecord?id=CVE-2025-40907
- https://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library technical-descriptionExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/04/23/4 | mailing-listMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2025-40907 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2366847 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-15438 | Advisory | |
| https://github.com/FastCGI-Archives/fcgi2/issues/67 | issue-trackingExploitIssue Tracking | |
| https://github.com/FastCGI-Archives/fcgi2/releases/tag/2.4.5 | patchRelease Notes | |
| https://github.com/perl-catalyst/FCGI/issues/14 | issue-trackingExploitIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-40907 | ||
| https://patch-diff.githubusercontent.com/raw/FastCGI-Archives/fcgi2/pull/74.patch | patch | |
| https://www.cve.org/CVERecord?id=CVE-2025-40907 | ||
| https://www.synacktiv.com/en/publications/cve-2025-23016-exploiting-the-fastcgi-library | technical-descriptionExploitThird Party Advisory |
Change history (0)
No recorded changes yet.