Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 39: FEDORA-2023-9adc4be8b0 Minor: Mosquitto Memory Leak Fix

fedora
Calendar Grey September 15, 2023
Dist Fedora Esm H88
The latest Mosquitto 2.0.17 update for Fedora addresses multiple bugs and resolves critical memory leak vulnerabilities. Prompt installation is advised.
2.0.17 Broker: * Fix `max_queued_messages 0` stopping clients from receiving messages * Fix `max_inflight_messages` not being set correctly

Summary

Mosquitto is an open source message broker that implements the MQ Telemetry

Transport protocol version 3.1 and 3.1.1 MQTT provides a lightweight method

of carrying out messaging using a publish/subscribe model. This makes it

suitable for "machine to machine" messaging such as with low power sensors

or mobile devices such as phones, embedded computers or micro-controllers

like the Arduino.

Update Information:

2.0.17 Broker: * Fix `max_queued_messages 0` stopping clients from receiving messages * Fix `max_inflight_messages` not being set correctly. Apps: * Fix `mosquitto_passwd -U` backup file creation. 2.0.16 Security: * CVE-2023-28366: Fix memory leak in broker when clients send multiple QoS 2 messages with the same message ID, but then never respond to the PUBREC commands. * CVE-2023-0809: Fix excessive memory being allocated based on malicious initial packets that are not CONNECT packets. * CVE-2023-3592: Fix memory leak when clients send v5 CONNECT packets with a will message that contains invalid property types. * Broker will now reject Will messages that attempt to publish to $CONTROL/. * Broker now validates usernames provided in a TLS certificate or TLS-PSK identity are valid UTF-8. * Fix potential crash when loading invalid persistence file. * Library will no longer allow single level wildcard certificates, e.g. *.com Broker: * Fix $SYS messages being expir...

Change Log

* Wed Aug 23 2023 Peter Robinson - 2.0.17-1 - Update to 2.0.17

References

Fedora Update Notification FEDORA-2023-9adc4be8b0 2023-09-15 18:36:13.238037 Name : mosquitto Product : Fedora 39 Version : 2.0.17 Release : 1.fc39 URL : https://mosquitto.org/ Summary : Open Source MQTT v5/v3.1.x Broker Description : Mosquitto is an open source message broker that implements the MQ Telemetry Transport protocol version 3.1 and 3.1.1 MQTT provides a lightweight method of carrying out messaging using a publish/subscribe model. This makes it suitable for "machine to machine" messaging such as with low power sensors or mobile devices such as phones, embedded computers or micro-controllers like the Arduino.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9adc4be8b0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Name: mosquitto
Product: Fedora 39
Version: 2.0.17
Release: 1.fc39
Summary: Open Source MQTT v5/v3.1.x Broker

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here