CVE-2020-35680: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 3.7% chance of exploitation in the next 30 days.
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.
Affected products
- Fedoraproject Fedora: version 32 only; version 33 only
- OpenSMTPD OpenSMTPD: before 6.8.0 (fixed in 6.8.0); version 6.8.0 only
Published 2020-12-24. Last modified 2026-06-17.