๐Ÿ” CVE Alert

CVE-2026-67607

MEDIUM 5.9

LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached thread id reuse, resulting in daemon destabilization or crash which can lead to a denial of service. The 2.3.1 patch only narrowed the timing window (an extra re-check and reordered cleanup), it never added the missing lock, so the underlying race remains.

CWE CWE-367
Vendor hfiref0x
Product lightftp
Published Jul 31, 2026
Last Updated Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for hfiref0x lightftp

Be the first to know when new medium vulnerabilities affecting hfiref0x lightftp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

hfiref0x / LightFTP
0 โ‰ค 2.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/zeroscience/tuktam#real-world-case-study-lightftp-cve-2024-11144 vulncheck.com: https://www.vulncheck.com/advisories/lightftp-race-condition-dos-via-worker-thread-cleanup

Credits

Gjoko Krstic of Zero Science Lab