CVE-2025-62875: Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock
Published Oct 31, 2025
·Updated
An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD.
This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.
Affected Software
4 affected components
OpenSMTPD OpenSMTPD<7.8.0p0-1.1
openSUSE Tumbleweed>?
OpenSMTPD OpenSMTPD=7.7.0-p0
openSUSE Tumbleweed<7.8.0p0-1.1
Remediation
Patch Available
Event History
Nov 20, 2025
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62875?
CVE-2025-62875 is classified as a local denial-of-service vulnerability in OpenSMTPD that can be exploited by local users.
2
How do I fix CVE-2025-62875?
To address CVE-2025-62875, update OpenSMTPD to the latest version beyond 7.8.0p0-1.1 on affected systems.
3
Which versions of OpenSMTPD are affected by CVE-2025-62875?
CVE-2025-62875 affects OpenSMTPD versions up to but not including 7.8.0p0-1.1.
4
Can CVE-2025-62875 be exploited remotely?
No, CVE-2025-62875 can only be exploited by local users who have access to the system.
5
Which operating systems are impacted by CVE-2025-62875?
CVE-2025-62875 impacts openSUSE Tumbleweed versions from an unspecified version before 7.8.0p0-1.1.