CVE-2020-6017: Valvesoftware Game Networking Sockets
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.
Affected products
- Valvesoftware Game Networking Sockets: before 1.2.0 (fixed in 1.2.0)
Published 2020-12-03. Last modified 2026-06-17.