Описание
The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.
A memory leak vulnerability was found in Eclipse Mosquitto. This issue is triggered by malicious initial packets or certain client actions and may allow a remote attacker to the deplete system resources causing memory exhaustion, leading to a disruption in services and a denial of service condition.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 3 | mosquitto | Not affected | ||
| Red Hat Integration Camel K 1 | mosquitto | Not affected | ||
| Red Hat Satellite 6.13 for RHEL 8 | mosquitto | Fixed | RHSA-2024:1061 | 29.02.2024 |
| Red Hat Satellite 6.13 for RHEL 8 | mosquitto | Fixed | RHSA-2024:1061 | 29.02.2024 |
| Red Hat Satellite 6.14 for RHEL 8 | mosquitto | Fixed | RHSA-2024:0797 | 13.02.2024 |
| Red Hat Satellite 6.14 for RHEL 8 | mosquitto | Fixed | RHSA-2024:0797 | 13.02.2024 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.
The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.
The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a ...
The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.
Уязвимость брокера сообщений Eclipse Mosquitto, связанная с ошибкой освобождения памяти, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3