The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a
memory leak that can be abused remotely when a client sends many QoS 2
messages with duplicate message IDs, and fails to respond to PUBREC
commands. This occurs because of mishandling of EAGAIN from the libc
send function.
- https://bugs.mageia.org/show_bug.cgi?id=34116
- https://www.cve.org/CVERecord?id=CVE-2023-28366
- 9/core/mosquitto-2.0.21-1.mga9
Get the latest Linux and open source security news straight to your inbox.