There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2023-29323:
(needs triaging)
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
- CVE-2025-62875:
(needs triaging)
An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD. This issue affects openSUSE Tumbleweed: from ? before 7.8.0p0-1.1.
You can find information about how to handle these issues in the security team's documentation.