Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian 11: DLA-4059-1 moderate: mosquitto MQTT broker crash

debian lts
Calendar Grey February 20, 2025
Dist Debian Esm H88
Ubuntu Security Notice USN-4898-1 addresses vulnerabilities in the OpenSSL library. It is advised to update your system.
The following vulnerabilities have been discovered in the package mosquitto, MQTT message broker

Summary

The following vulnerabilities have been discovered in the package
mosquitto, MQTT message broker.

CVE-2024-3935

If a Mosquitto broker is configured to create an outgoing bridge
connection, and that bridge connection has an incoming topic
configured that makes use of topic remapping, then if the remote
connection sends a crafted PUBLISH packet to the broker a double
free will occur with a subsequent crash of the broker.


CVE-2024-10525

If a malicious broker sends a crafted SUBACK packet with no reason
codes, a client using libmosquitto may make out of bounds memory
access when acting in its on_subscribe callback. This affects the
mosquitto_sub and mosquitto_rr clients.


For Debian 11 bullseye, these problems have been fixed in version
2.0.11-1+deb11u2.

We recommend that you upgrade your mosquitto packages.

For the detailed security status of mosquitto please refer to
its security tracker page at:

Read the Full Advisory


Package: mosquitto
Version: 2.0.11-1+deb11u2
CVE ID: CVE-2024-3935 CVE-2024-10525

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here