Bug ID 1232635
Summary VUL-0: CVE-2024-3935: mosquitto: double free and subsequent crash when running under bridge mode and processing remote connections
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/426290/
OS Other
Status NEW
Severity Major
Priority P5 - None
Component Security
Assignee mardnh@gmx.de
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker
is configured to create an outgoing bridge connection, and that bridge
connection has an incoming topic configured that makes use of topic remapping,
then if the remote connection sends a crafted PUBLISH packet to the broker a
double free will occur with a subsequent crash of the broker.

References:
https://mosquitto.org/blog/2024/10/version-2-0-19-released/
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-3935
https://www.cve.org/CVERecord?id=CVE-2024-3935
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/197


You are receiving this mail because: