CVE-2025-61908: Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a filter expression to crash the Icinga 2 daemon. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61908?
CVE-2025-61908 is considered a critical vulnerability due to its potential to cause segmentation faults in Icinga 2.
How do I fix CVE-2025-61908?
To fix CVE-2025-61908, upgrade Icinga 2 to version 2.15.1 or later.
What versions of Icinga 2 are affected by CVE-2025-61908?
CVE-2025-61908 affects Icinga 2 versions from 2.10.0 up to but not including 2.15.1.
Can CVE-2025-61908 be exploited remotely?
Yes, CVE-2025-61908 can be exploited by any API user accessing affected API endpoints.
What is the impact of CVE-2025-61908?
The impact of CVE-2025-61908 is a denial of service due to segmentation faults when an invalid reference is created.