Toxcore · Toxcore · CVE-2018-25021
**Name of the Vulnerable Software and Affected Versions**
toxcore versions prior to 0.2.8
**Description**
The TCP Server module in toxcore does not free the TCP priority queue under certain conditions, allowing a remote attacker to exhaust the system's memory and cause a denial of service (DoS).
**Recommendations**
For versions prior to 0.2.8, update to version 0.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the TCP Server module to minimize the risk of exploitation.