CVE-2020-6079: Debian Linux

High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.

An exploitable denial-of-service vulnerability exists in the resource allocation handling of Videolabs libmicrodns 0.1.0. When encountering errors while parsing mDNS messages, some allocated data is not freed, possibly leading to a denial-of-service condition via resource exhaustion. An attacker can send one mDNS message repeatedly to trigger this vulnerability through decoding of the domain name performed by rr_decode.

Affected products

  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Videolabs Libmicrodns: version 0.1.0 only

Published 2020-03-24. Last modified 2026-10-08.