Integer Overflow Vulnerability in FastCGI (CVE-2025-23016)

ISGroup Cybersecurity

FastCGI is an important protocol that improves web server performance by maintaining persistent connections between web servers and application servers. It is widely used in embedded systems with limited computational resources, such as network cameras, routers, and IoT devices. Due to its lightweight nature, FastCGI is often implemented in environments where security resources are limited, making vulnerabilities particularly concerning.

This vulnerability affects the core FastCGI library written in C, not PHP-FPM (which implements its own version of the FCGI protocol). Many IoT devices and embedded systems use the vulnerable library, exposing numerous devices if they are not properly updated.

ProductFastCGI
Date2025-05-07 14:18:55
Information
  • Fix Available
  • Active Exploitation

Technical Summary

The vulnerability is present in the ReadParams function of the FastCGI library. This function processes parameters received from web servers, parsing the name and value lengths before allocating memory for them.

The vulnerability chain works as follows:

  1. The ReadParams function reads the length of the parameter name and value from the input stream.
  2. If either length has the high bit set (≥ 0x80), it is processed as a 32-bit integer.
  3. Memory is then allocated with malloc(nameLen + valueLen + 2) to store both strings, an equals sign, and the null terminator.
  4. On 32-bit systems, when both nameLen and valueLen are close to the maximum value (0x7FFFFFFF), their sum plus 2 causes an integer overflow.
  5. This results in a very small allocation (typically 0x10 bytes) instead of the gigabytes required.
  6. The function then attempts to read the entire parameter name and value into this undersized buffer.
  7. This creates an attacker-controllable heap buffer overflow.

The most critical aspect is that this overflow allows for the overwriting of adjacent structures on the heap, specifically the FCGX_Stream structure which contains function pointers. By overwriting the fillBuffProc function pointer with the address of system() and controlling the first parameter (the stream itself, which can contain shell commands), remote code execution is achieved.

The vulnerability affects all versions of the FastCGI library prior to 2.4.5.

Attack Vector

The attack requires:

  1. Direct access to a FastCGI socket
  2. The ability to send FastCGI parameters constructed with specific sizes

Although FastCGI sockets should only be accessible locally, many implementations erroneously expose these sockets to remote connections. This is particularly true in some embedded systems and misconfigured web servers, such as the lighttpd example mentioned in the report, where many tutorials suggest insecure configurations.

Recommendations

To mitigate this vulnerability, the following steps must be taken:

  1. Update the FastCGI library: Upgrade to version 2.4.5 or later, which includes the fixes for this vulnerability.

  2. Configure web servers securely:

    • Use UNIX sockets instead of TCP sockets whenever possible
    • If TCP sockets are necessary, restrict access to localhost only
    • Implement proper network segmentation to prevent direct access to FastCGI services
  3. Implement defense-in-depth measures:

    • Enable all available system protections (ASLR, PIE, RELRO, etc.)
    • Run FastCGI applications with minimal privileges
    • Consider using application firewalls to filter malicious requests
  4. Verify existing implementations:

    • Check for FastCGI sockets exposed to the network
    • Verify that web server configurations do not include options like check-local => "disable" without adequate security controls
    • Inspect documentation and tutorials to ensure deployment practices are secure

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert