CVE-2025-54939: High severity LiteSpeed LSQUIC Library vulnerability
Published Aug 1, 2025
·Updated
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquicenginepacketin memory leak.
Affected Software
5 affected components
LiteSpeed LSQUIC Library<4.3.1
Litespeedtech Litespeed Web Adc<3.3.1
Litespeedtech Litespeed Web Server<6.3.4
Litespeedtech Lsquic<4.3.1
Litespeedtech Openlitespeed<1.8.4
Event History
Aug 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-54939?
CVE-2025-54939 has been identified as a medium severity vulnerability due to its potential to cause memory leaks.
2
How do I fix CVE-2025-54939?
To fix CVE-2025-54939, upgrade the LiteSpeed LSQUIC Library to version 4.3.1 or later.
3
What specific issue does CVE-2025-54939 cause in the LSQUIC Library?
CVE-2025-54939 causes a memory leak through the lsquic_engine_packet_in function in the LSQUIC Library.
4
Which versions of the LSQUIC Library are affected by CVE-2025-54939?
CVE-2025-54939 affects all versions of the LiteSpeed LSQUIC Library prior to 4.3.1.
5
Is CVE-2025-54939 a zero-day vulnerability?
CVE-2025-54939 is not categorized as a zero-day vulnerability, as it has been publicly reported and addressed.