What is CVE-2026-67192?
Xlight FTP Server versions before 3.9.5 contain a pre-authentication stack buffer overflow vulnerability. It allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets with an unvalidated length field when a GCM cipher is negotiated. Upgrading to version 3.9.5 or later is recommended.
Azərbaycanca: Xlight FTP Server-in 3.9.5-dən əvvəlki versiyalarında autentifikasiyadan əvvəl stack buffer overflow zəifliyi aşkar edilib. Bu, GCM şifrəsi müzakirə edilərkən xüsusi hazırlanmış SSH paketləri vasitəsilə autentifikasiya olunmamış hücumçulara stack yaddaşını korlamağa imkan verir. Serveri 3.9.5 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Xlight
FAQ2
What must an attacker do to exploit the pre-authentication stack buffer overflow vulnerability in Xlight FTP Server?
The attacker must send malformed SSH packets when a GCM cipher is negotiated.
To which version should one upgrade to fix the CVE-2026-67192 vulnerability?
Upgrading to version 3.9.5 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.