The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libtoxcore-dev",
"binary_version": "0.2.10-1build2"
},
{
"binary_name": "libtoxcore2",
"binary_version": "0.2.10-1build2"
},
{
"binary_name": "libtoxcore2-dbgsym",
"binary_version": "0.2.10-1build2"
},
{
"binary_name": "toxcore-utils",
"binary_version": "0.2.10-1build2"
},
{
"binary_name": "toxcore-utils-dbgsym",
"binary_version": "0.2.10-1build2"
}
]
}