Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918540 (CVE-2023-0809, CVE-2023-28366, CVE-2023-3592) - <app-misc/mosquitto-2.0.17: multiple vulnerabilities
Summary: <app-misc/mosquitto-2.0.17: multiple vulnerabilities
Alias: CVE-2023-0809, CVE-2023-28366, CVE-2023-3592
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: B3 [stable]
Depends on: 916239
  Show dependency tree
Reported: 2023-11-25 17:51 UTC by John Helmert III
Modified: 2023-11-25 17:52 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-25 17:51:22 UTC

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.


In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.


In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

Please stabilize >2.0.16.