CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6426-1 icinga2 - security update

unknownCVE-2025-61909
Multiple vulnerabilities were discovered in Icinga 2, a monitoring and alerting system, which may result in denial of service, information disclosure, privilege escalation or the compromise of a monitoring node. The fix for CVE-2025-61909 changes /etc/logrotate.d/icinga2, which is a configuration file. If it was modified locally, dpkg will not replace it and the fix will not take effect. After the upgrade, please make sure the postrotate section is updated. https://security-tracker.debian.org/tracker/DSA-6426-1

CSIRTS triage

What
Multiple vulnerabilities in Icinga 2 may result in denial of service, information disclosure, privilege escalation, or compromise of a monitoring node.
Who is affected
Deployments of Icinga 2 using the affected configuration files.
Urgency
Moderate; the fix for CVE-2025-61909 requires manual intervention on systems with locally modified logrotate configuration to be effective.
Action
Upgrade to the patched version and verify that the postrotate section in /etc/logrotate.d/icinga2 has been updated if the file was locally modified.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Icinga 2

Get an email when a new Icinga 2 advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-10
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00337.html

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-61909coverage & exploitation statusNVD · CVE.org

More from Debian Security Advisories