The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.2.10-1build2", "binary_name": "libtoxcore-dev" }, { "binary_version": "0.2.10-1build2", "binary_name": "libtoxcore2" }, { "binary_version": "0.2.10-1build2", "binary_name": "libtoxcore2-dbgsym" }, { "binary_version": "0.2.10-1build2", "binary_name": "toxcore-utils" }, { "binary_version": "0.2.10-1build2", "binary_name": "toxcore-utils-dbgsym" } ] }