{"id":"UBUNTU-CVE-2020-26164","details":"In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.","modified":"2026-05-20T16:04:20.377417280Z","published":"2020-10-07T19:15:00Z","upstream":["CVE-2020-26164"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-26164"},{"type":"REPORT","url":"https://kde.org/info/security/advisory-20201002-1.txt"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/f183b5447bad47655c21af87214579f03bf3a163"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/b279c52101d3f7cc30a26086d58de0b5f1c547fa"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/d35b88c1b25fe13715f9170f18674d476ca9acdc"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/b496e66899e5bc9547b6537a7f44ab44dd0aaf38"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/5310eae85dbdf92fba30375238a2481f2e34943e"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/721ba9faafb79aac73973410ee1dd3624ded97a5"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/ae58b9dec49c809b85b5404cee17946116f8a706"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/66c768aa9e7fba30b119c8b801efd49ed1270b0a"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/85b691e40f525e22ca5cc4ebe79c361d71d7dc05"},{"type":"REPORT","url":"https://invent.kde.org/network/kdeconnect-kde/-/commit/48180b46552d40729a36b7431e97bbe2b5379306"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1176268"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/commit/024e5f23db8d8ad3449714b906b46094baaffb89"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/commit/4fbd01a3d44a0bcca888c49a77ec7cfd10e113d7"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/commit/542d94a70c56aa386c8d4d793481ce181b0422e8"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/commit/613899be24b6e2a6b3e5cc719efce8ae8a122991"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/commit/8112729eb0f13e6947984416118531078e65580d"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/commit/ce0f00fc2d3eccb51d0af4eba61a4f60de086a59"},{"type":"REPORT","url":"https://github.com/KDE/kdeconnect-kde/releases"},{"type":"REPORT","url":"https://kdeconnect.kde.org/official/"},{"type":"REPORT","url":"https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00014.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-26164"}],"affected":[{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"0.8-0ubuntu5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.3-0ubuntu2","1.2.1-0ubuntu1","1.2.1-0ubuntu2","1.3.0-0ubuntu1","1.3.1-0ubuntu0.1","1.3.3-0ubuntu0.18.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.3-0ubuntu0.18.04.1","binary_name":"kdeconnect"},{"binary_name":"kdeconnect-plasma","binary_version":"1.3.3-0ubuntu0.18.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.5-0ubuntu1","1.4-0ubuntu1","1.4-0ubuntu2","1.4-0ubuntu3","1.4-0ubuntu4","1.4-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"1.4-0ubuntu5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["21.08.1-0ubuntu1","21.08.1-0ubuntu2","21.08.3-0ubuntu1","21.08.3-1ubuntu1","21.11.80-0ubuntu1","21.11.90-0ubuntu1","21.11.90-0ubuntu2","21.12.0-0ubuntu1","21.12.1-0ubuntu1","21.12.2-0ubuntu1","21.12.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"21.12.3-0ubuntu1"},{"binary_name":"nautilus-kdeconnect","binary_version":"21.12.3-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["23.08.1-0ubuntu1","23.08.2-0ubuntu1","23.08.3-0ubuntu1","23.08.4-0ubuntu1","23.08.5-0ubuntu1","23.08.5-0ubuntu4","23.08.5-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"23.08.5-0ubuntu5"},{"binary_name":"nautilus-kdeconnect","binary_version":"23.08.5-0ubuntu5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["24.12.3-0ubuntu2","25.04.0-0ubuntu1","25.04.0-0ubuntu2","25.04.1-0ubuntu1","25.04.2-0ubuntu2","25.04.2-1ubuntu1","25.04.3-0ubuntu1","25.07.80-0ubuntu1","25.07.90-0ubuntu1","25.08.0-0ubuntu1","25.08.1-0ubuntu1","25.08.1-0ubuntu2","25.08.1-0ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"25.08.1-0ubuntu2.1"},{"binary_name":"kdeconnect-libs","binary_version":"25.08.1-0ubuntu2.1"},{"binary_name":"nautilus-kdeconnect","binary_version":"25.08.1-0ubuntu2.1"},{"binary_name":"qml6-module-org-kde-kdeconnect","binary_version":"25.08.1-0ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["25.08.1-0ubuntu2","25.08.2-0ubuntu2","25.08.3-0ubuntu1","25.11.80-0ubuntu1","25.11.80-0ubuntu2","25.11.90-0ubuntu1","25.12.0-0ubuntu1","25.12.1-0ubuntu1","25.12.1-0ubuntu2","25.12.2-0ubuntu1","25.12.2-0ubuntu3","25.12.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"25.12.3-0ubuntu1"},{"binary_name":"kdeconnect-libs","binary_version":"25.12.3-0ubuntu1"},{"binary_version":"25.12.3-0ubuntu1","binary_name":"nautilus-kdeconnect"},{"binary_version":"25.12.3-0ubuntu1","binary_name":"qml6-module-org-kde-kdeconnect"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-26164.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}