AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:27.613Z and has not been modified since then. LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and [truncated]
CVE-2026-67607 is a high-severity vulnerability in LightFTP 2.3.1, a residual race condition in the worker_thread_cleanup() function that allows remote unauthenticated attackers to destabilize or crash the daemon, resulting in a denial of service. The vulnerability is a result of an incomplete fix for CVE-2024-11144, where the patch narrowed the timing window but did not add the necessary mutex lock, leav [truncated]