CVE-2020-35679: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
Affected products
- Fedoraproject Fedora: version 32 only; version 33 only
- OpenSMTPD OpenSMTPD: before 6.8.0 (fixed in 6.8.0); version 6.8.0 only
Published 2020-12-24. Last modified 2026-06-17.