CVE-2026-63090

HIGH

ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly

Title source: cna
STIX 2.1

Description

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution by sending crafted SFTP packet fragments exceeding the 16 KB reassembly buffer in the fxp.c component. Attackers can supply oversized fragments to trigger an incorrectly conditioned reallocation, corrupt pool freelist metadata, overwrite the root_fs BSS global pointer to reference a fake filesystem struct, and redirect pr_fsio_stat() to system() via a crafted RENAME request.

References (6)

Core 6
Core References
Release Notes release-notes
Release Notes
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
Issue Tracking issue-tracking
Pull Request
https://github.com/proftpd/proftpd/issues/2190
Release Notes patch release-notes
v1.3.10rc3 Pre-release Tag
https://github.com/proftpd/proftpd/releases/tag/v1.3.10rc3-3
Release Notes patch release-notes
v1.3.9c Release Tag
https://github.com/proftpd/proftpd/releases/tag/v1.3.9c

Scores

CVSS v3 8.8
EPSS 0.0046
EPSS Percentile 37.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (3)
proftpd/proftpd 1.3.10 rc1 (2 CPE variants)
proftpd/proftpd < 1.3.9c (2 CPE variants)
proftpd/proftpd 1.3.10rc1 - 1.3.10rc3
Published Jul 20, 2026
Tracked Since Jul 20, 2026