Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918540 (CVE-2023-0809, CVE-2023-28366, CVE-2023-3592) - <app-misc/mosquitto-2.0.17: multiple vulnerabilities
Summary: <app-misc/mosquitto-2.0.17: multiple vulnerabilities
Alias: CVE-2023-0809, CVE-2023-28366, CVE-2023-3592
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: B3 [glsa+]
Depends on: 916239
  Show dependency tree
Reported: 2023-11-25 17:51 UTC by John Helmert III
Modified: 2024-01-07 09:15 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-25 17:51:22 UTC

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.


In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.


In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

Please stabilize >2.0.16.
Comment 1 Larry the Git Cow gentoo-dev 2023-11-29 17:41:41 UTC
The bug has been referenced in the following commit(s):

commit 4d0f6ea3c6a5f6216ea75a4c6c7e960f7f2b08f3
Author:     Matt Turner <>
AuthorDate: 2023-11-29 17:40:36 +0000
Commit:     Matt Turner <>
CommitDate: 2023-11-29 17:41:14 +0000

    app-misc/mosquitto: Drop old versions
    Signed-off-by: Matt Turner <>

 app-misc/mosquitto/Manifest                   |   2 -
 app-misc/mosquitto/mosquitto-2.0.15-r1.ebuild | 127 --------------------------
 app-misc/mosquitto/mosquitto-2.0.17.ebuild    | 127 --------------------------
 3 files changed, 256 deletions(-)
Comment 2 Larry the Git Cow gentoo-dev 2024-01-07 09:13:51 UTC
The bug has been referenced in the following commit(s):

commit 849726d04fc8e25ea56d3c54858506f82619e186
Author:     GLSAMaker <>
AuthorDate: 2024-01-07 09:13:27 +0000
Commit:     Hans de Graaff <>
CommitDate: 2024-01-07 09:13:46 +0000

    [ GLSA 202401-09 ] Eclipse Mosquitto: Multiple Vulnerabilities
    Signed-off-by: GLSAMaker <>
    Signed-off-by: Hans de Graaff <>

 glsa-202401-09.xml | 44 ++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 44 insertions(+)