The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mosquitto | Mar 26, 2024 | Sep 1, 2023 |
| Debian | — | Upgrade mosquitto | Oct 3, 2023 | Sep 1, 2023 |
| Gentoo Linux | — | Upgrade app-misc/mosquitto. | Jan 8, 2024 | Sep 1, 2023 |
| Ubuntu | — | Upgrade mosquittoUpgrade mosquitto (Ubuntu Pro) | Nov 22, 2023 | Sep 1, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub