The following vulnerabilities have been discovered in the package
mosquitto, MQTT message broker.
CVE-2024-3935
If a Mosquitto broker is configured to create an outgoing bridge
connection, and that bridge connection has an incoming topic
configured that makes use of topic remapping, then if the remote
connection sends a crafted PUBLISH packet to the broker a double
free will occur with a subsequent crash of the broker.
CVE-2024-10525
If a malicious broker sends a crafted SUBACK packet with no reason
codes, a client using libmosquitto may make out of bounds memory
access when acting in its on_subscribe callback. This affects the
mosquitto_sub and mosquitto_rr clients.
For Debian 11 bullseye, these problems have been fixed in version
2.0.11-1+deb11u2.
We recommend that you upgrade your mosquitto packages.
For the detailed security status of mosquitto please refer to
its security tracker page at:
Get the latest Linux and open source security news straight to your inbox.