CVE Vulnerabilities

CVE-2025-61908

NULL Pointer Dereference

Published: Oct 16, 2025 | Modified: Nov 26, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a filter expression to crash the Icinga 2 daemon. A fix is included in the following Icinga 2 versions: 2.15.1, 2.14.7, and 2.13.13.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Icinga Icinga 2.10.0 (including) 2.13.13 (excluding)
Icinga Icinga 2.14.0 (including) 2.14.7 (excluding)
Icinga Icinga 2.15.0 (including) 2.15.1 (excluding)
Icinga2 Ubuntu upstream *

Potential Mitigations

References