CVE-2016-6254: Collectd

Critical severity, CVSS 9.1. EPSS: 5.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

Affected products

  • Collectd Collectd: from 5.4.0, before 5.4.3 (fixed in 5.4.3); from 5.5.0, before 5.5.2 (fixed in 5.5.2)
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 23 only; version 24 only

Published 2016-08-19. Last modified 2026-06-17.