Home / mailingsPDF  

[SECURITY] [DSA 6426-1] icinga2 security update

Posted on 10 August 2026
Debian Security Advisory

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6426-1 security@debian.org
https://www.debian.org/security/ Sebastiaan Couwenberg
August 10, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : icinga2
CVE ID : CVE-2025-61907 CVE-2025-61908 CVE-2025-61909
CVE-2026-61550 CVE-2026-61551 CVE-2026-61552

Multiple vulnerabilities were discovered in Icinga 2, a monitoring and
alerting system, which may result in denial of service, information
disclosure, privilege escalation or the compromise of a monitoring node.

The fix for CVE-2025-61909 changes /etc/logrotate.d/icinga2, which is a
configuration file. If it was modified locally, dpkg will not replace it
and the fix will not take effect. After the upgrade, please make sure the
postrotate section is updated.

For the stable distribution (trixie), these problems have been fixed in
version 2.14.6-1+deb13u1.

We recommend that you upgrade your icinga2 packages.

For the detailed security status of icinga2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/icinga2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org

 

TOP