PT-2024-38981 · Eclipse+3 · Eclipse Mosquitto+3

·

CVE-2024-8376

·

Published

2024-10-11

·

Updated

2026-03-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Eclipse Mosquitto versions up to 2.0.18a
Description: The issue allows an attacker to cause memory leaking, segmentation fault, or heap-use-after-free by sending specific sequences of packets, including "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE", and "PUBLISH" packets.
Recommendations: For Eclipse Mosquitto versions up to 2.0.18a, consider restricting the handling of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE", and "PUBLISH" packets until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Handling of Exceptional Conditions

Memory Leak

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1041
ALT-PU-2025-3746
CVE-2024-8376
OESA-2024-2415
OESA-2024-2416
OESA-2024-2417
OESA-2024-2418
RHSA-2024:8718
RHSA-2024:8719
RHSA-2024:8906

Affected Products

Alt Linux
Debian
Eclipse Mosquitto
Red Os