URGENT — Security Advisory
A critical privilege-escalation vulnerability has been identified in LiteSpeed Web Server Enterprise. On shared-hosting servers, a malicious low-privilege website user could potentially gain root-level access to the server.
This could allow an attacker to access or alter other hosted websites and the server itself.
This issue can bypass expected account isolation controls, including CageFS, allowing a malicious website user to potentially escape its restricted environment and gain root-level access to the server.
Affected: LiteSpeed Web Server Enterprise installations prior to v6.3.7
Status: Fix available
Severity: Critical
ACTION REQUIRED (immediately)
We strongly recommend upgrading all affected LiteSpeed Enterprise installations to:
LiteSpeed Web Server Enterprise 6.3.7 or later
The v6.3.7 update includes the following:
[Security] Enhance lscgid request authentication and validation.
[Security] Apply stronger validation of internal redirect URL.
[Security] Block setting of important internal-use environment variables from .htaccess.
[Feature] Enable post-quantum cryptography key exchange.
[Improvement] Add support for the MKCALENDAR request method.
[Bug fix] Address a race condition corner case for ModSecurity engine.
[Bug fix] Address an internal URL cache corner case.
[Bug fix] Improve Node.js process management to avoid lingering idle workers.
[Bug fix] Address HTTP/3 idle connection timeout issue.
[Bug fix] Address a namespace issue for natively configured vhost.
[Bug fix] Address a corner case in SHM locking.
Important Post-Upgrade Note
The stable v6.3.7 release includes an adjustment that permits tightly controlled, root-owned binaries to continue operating safely.
After upgrading, please review your server for unusual CGI activity or piped logging behavior and verify that server-level logging continues to function normally.
Please take action as soon as possible to secure your servers. If you need assistance with the upgrade or have concerns about possible exposure, our support team is ready to help.
Thank you for your immediate attention to this critical security update.
LiteSpeed Team