smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-opensmtpd | Oct 1, 2024 | Dec 24, 2020 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Dec 24, 2020 | |
| Debian | debian-upgrade-opensmtpd | Jul 30, 2024 | Dec 24, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-mail-mta-opensmtpd | May 28, 2021 | Dec 24, 2020 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Dec 24, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub