CVE-2026-70637 PUBLISHED

LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c

Assigner: VulnCheck
Reserved: 04.08.2026 Published: 06.08.2026 Updated: 06.08.2026

LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker threads concurrently operate on the same fields in worker_thread_cleanup, allowing stale file descriptors to be reassigned by the OS and subsequently used by worker threads on unrelated resources, resulting in potential denial of service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor hfiref0x
Product LightFTP
Versions Default: affected
  • affected from 0 to 2.4 (incl.)
  • affected from 0 to d28c5e08aa4bd128737d35cc6ee0f9630a910ed5 (incl.)

Credits

  • grant_Y (@grant-yim) finder
  • Gjoko Krstic of Zero Science Lab reporter

References

Problem Types

  • CWE-820 Missing Synchronization CWE