VulnerabilityAnalyzed
CVE-2025-62875
An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD.
MEDIUM 6.9EPSS 0.18%
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.
- CVSS 4.0
- 6.9 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754
- Affected
- opensmtpd/opensmtpd · opensuse/tumbleweed
- Source
- meissner@suse.de
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-62875Issue Tracking, Patch
- https://security.opensuse.org/2025/10/31/opensmtpd-local-DoS.htmlExploit, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/10/31/3Exploit, Mailing List, Third Party Advisory
- https://security.opensuse.org/2025/10/31/opensmtpd-local-DoS.html#reproducerExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.