← Vulnerability feed

Vulnerability record · CVE-2020-8794 · published 25 February 2020

CVE-2020-8794: OpenSMTPD out-of-bounds read in mta_io enables remote code execution

Opensmtpd · Opensmtpd

OpenSMTPD before 6.6.4 contains an out-of-bounds read in mta_io in mta_session.c when handling multi-line replies. The flaw affects the client side of OpenSMTPD, but a server can be attacked because the server launches the client code during bounce handling. It matters because it can lead to remote code execution on an internet-facing mail server.

9.8 CVSS 3.1 Critical EPSS 89% · top 0.2% CWE-125 · Out-of-bounds read
9.8CVSS 3.1 base score, v2 10.0
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
22References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and very high EPSS plus public exploit references make this a critical patching priority.

What it is

OpenSMTPD before 6.6.4 contains an out-of-bounds read in mta_io in mta_session.c when handling multi-line replies. The flaw affects the client side of OpenSMTPD, but a server can be attacked because the server launches the client code during bounce handling. It matters because it can lead to remote code execution on an internet-facing mail server.

Impact

An attacker can trigger the out-of-bounds read and potentially execute code in the context of the OpenSMTPD process. Given the CVSS vector, this can result in full compromise of confidentiality, integrity and availability.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N). It is reached by causing the server to process a crafted multi-line reply through the client code path invoked during bounce handling.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.889 (99.77th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade OpenSMTPD to 6.6.4 or later, or apply the vendor patch for your distribution (Ubuntu USN-4294-1, Debian DSA-4634, Fedora advisory).
  • If immediate patching is not possible, restrict network access to the SMTP service to trusted hosts and disable or limit bounce handling where feasible.
  • Monitor vendor advisories for OpenSMTPD, Ubuntu, Debian and Fedora for updated packages and re-apply as needed.
  • Verify the running OpenSMTPD version after patching and restart the service to ensure the fixed binary is loaded.

Detection

  • Inspect OpenSMTPD logs for crashes, abnormal terminations or restarts that could indicate exploitation attempts.
  • Monitor for unexpected child processes or outbound connections spawned by the OpenSMTPD service.
  • Use host-based detection to alert on unusual memory access patterns or crashes in the smtpd process.
  • Review mail queue and bounce-related activity for anomalous multi-line reply handling or malformed messages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/156633/OpenSMTPD-Out-Of-Bounds-Read-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2020/Feb/32 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/02/26/1 ExploitMailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/03/01/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/03/01/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/05/04/7 ExploitMailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPH4QU4DNVHA7ACFXMYFCEP
https://usn.ubuntu.com/4294-1/ PatchThird Party Advisory
https://www.debian.org/security/2020/dsa-4634 Third Party Advisory
https://www.openbsd.org/security.html Third Party Advisory
https://www.openwall.com/lists/oss-security/2020/02/24/5 ExploitMailing ListThird Party Advisory
http://packetstormsecurity.com/files/156633/OpenSMTPD-Out-Of-Bounds-Read-Local-Privilege-Escalation.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2020/Feb/32 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/02/26/1 ExploitMailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/03/01/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2020/03/01/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/05/04/7 ExploitMailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPH4QU4DNVHA7ACFXMYFCEP
https://usn.ubuntu.com/4294-1/ PatchThird Party Advisory
https://www.debian.org/security/2020/dsa-4634 Third Party Advisory
https://www.openbsd.org/security.html Third Party Advisory
https://www.openwall.com/lists/oss-security/2020/02/24/5 ExploitMailing ListThird Party Advisory

Track CVE-2020-8794 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8794), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.