CVE-2016-6254: Collectd
Critical severity, CVSS 9.1. EPSS: 5.7% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.
Affected products
- Collectd Collectd: from 5.4.0, before 5.4.3 (fixed in 5.4.3); from 5.5.0, before 5.5.2 (fixed in 5.5.2)
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 23 only; version 24 only
Published 2016-08-19. Last modified 2026-06-17.