CVE-2024-25767: Use After Free
Published Feb 26, 2024
·Updated
nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.
Affected Software
2 affected components
emqx Nanomq=0.21.2
nanomq nanomq
Event History
Feb 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25767?
CVE-2024-25767 is classified as a Medium severity vulnerability due to potential impacts on application stability.
2
How do I fix CVE-2024-25767?
To fix CVE-2024-25767, upgrade nanomq to version 0.21.3 or later, where the vulnerability has been patched.
3
What causes the CVE-2024-25767 vulnerability?
CVE-2024-25767 is caused by a Use-After-Free issue in the socket.c file of the nanomq library.
4
Is CVE-2024-25767 exploitable remotely?
Yes, CVE-2024-25767 can be exploited remotely if an attacker can send specially crafted input to the affected nanomq instance.
5
What software versions are affected by CVE-2024-25767?
CVE-2024-25767 affects nanomq version 0.21.2.