CVE-2023-28366
Summary
| CVE | CVE-2023-28366 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-01 16:15:00 UTC |
| Updated | 2024-01-07 10:15:00 UTC |
| Description | The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function. |
Risk And Classification
Problem Types: CWE-401
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.compass-security.com/fileadmin/Research/Advisories/2023_02_CSNC-2023-001_Eclipse_M... | MISC | www.compass-security.com | |
| GLSA-202401-09 | security.gentoo.org | ||
| Debian -- Security Information -- DSA-5511-1 mosquitto | DEBIAN | www.debian.org | |
| Comparing v2.0.15...v2.0.16 · eclipse/mosquitto · GitHub | MISC | github.com | |
| Version 2.0.16 released. | Eclipse Mosquitto | CONFIRM | mosquitto.org | |
| [SECURITY] Fedora 39 Update: mosquitto-2.0.17-1.fc39 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Fix for CVE-2023-28366 · eclipse/mosquitto@6113eac · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 39 Update: mosquitto-2.0.17-1.fc39 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199931 Ubuntu Security Notification for Mosquitto Vulnerabilities (USN-6492-1)
- 242923 Red Hat Update for Satellite 6.14.2 (RHSA-2024:0797)
- 242993 Red Hat Update for Satellite 6 (RHSA-2024:1061)
- 285295 Fedora Security Update for mosquitto (FEDORA-2023-9adc4be8b0)
- 378973 IBM Integration Bus Denial of Service (DoS) Vulnerability (7056456)
- 505895 Alpine Linux Security Update for mosquitto
- 6000171 Debian Security Update for mosquitto (DSA 5511-1)
- 710827 Gentoo Linux Eclipse Mosquitto Multiple Vulnerabilities (GLSA 202401-09)