DSA-6426-1 icinga2 - security update
Multiple vulnerabilities were discovered in Icinga 2, a monitoring and alerting system, which may result in denial of service, information disclosure, privilege escalation or the compromise of a monitoring node. The fix for CVE-2025-61909 changes /etc/logrotate.d/icinga2, which is a configuration file. If it was modified locally, dpkg will not replace it and the fix will not take effect. After the upgrade, please make sure the postrotate section is updated. https://security-tracker.debian.org/tracker/DSA-6426-1
CSIRTS triage
- What
- Multiple vulnerabilities in Icinga 2 may result in denial of service, information disclosure, privilege escalation, or compromise of a monitoring node.
- Who is affected
- Deployments of Icinga 2 using the affected configuration files.
- Urgency
- Moderate; the fix for CVE-2025-61909 requires manual intervention on systems with locally modified logrotate configuration to be effective.
- Action
- Upgrade to the patched version and verify that the postrotate section in /etc/logrotate.d/icinga2 has been updated if the file was locally modified.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Icinga 2
Get an email when a new Icinga 2 advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00337.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-619090.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-61909 | coverage & exploitation status | NVD · CVE.org |
More from Debian Security Advisories
- unknownDSA-6497-1 xorg-server - security update2026-09-12
- highDSA-6496-1 nginx - security update2026-09-12
- unknownDSA-6495-1 spip - security update2026-09-11
- unknownDSA-6494-1 kamailio - security update2026-09-11
- unknownDSA-6493-1 libevent - security update2026-09-11