MEDIUM
Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock
Published Nov 20, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.18%
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD.
This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.
Affected products
-
Affected
- ≥ ?, < 7.8.0p0-1.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SUSE | openSUSE Tumbleweed | unaffected | Affected
|
Configuration 2
- < 7.8.0p0-1.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://www.openwall.com/lists/oss-security/2025/10/31/3 ExploitMailing ListThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62875 Issue TrackingPatch
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-198303 Advisory
- https://security.opensuse.org/2025/10/31/opensmtpd-local-DoS.html ExploitThird Party Advisory
- https://security.opensuse.org/2025/10/31/opensmtpd-local-DoS.html#reproducer exploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/10/31/3 | ExploitMailing ListThird Party Advisory | |
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62875 | Issue TrackingPatch | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-198303 | Advisory | |
| https://security.opensuse.org/2025/10/31/opensmtpd-local-DoS.html | ExploitThird Party Advisory | |
| https://security.opensuse.org/2025/10/31/opensmtpd-local-DoS.html#reproducer | exploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner suse
Published Nov 20, 2025
Updated Nov 21, 2025
Reserved Oct 24, 2025
Link CVE-2025-62875
CISA Vulnrichment
Updated Nov 21, 2025
Red Hat
No data
GitHub
No data