CVE-2024-42651: Use After Free
Published Jul 29, 2025
·Updated
NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component subCtxhandle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
Affected Software
2 affected components
nanomq nanomq
emqx Nanomq=0.17.9
Event History
Jul 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42651?
CVE-2024-42651 has been classified as a critical vulnerability due to its potential to cause Denial of Service (DoS).
2
How do I fix CVE-2024-42651?
To fix CVE-2024-42651, it is recommended to upgrade NanoMQ to the latest version that addresses this vulnerability.
3
What component is affected by CVE-2024-42651?
CVE-2024-42651 affects the sub_Ctx_handle component within NanoMQ v0.17.9.
4
What type of vulnerability is CVE-2024-42651?
CVE-2024-42651 is categorized as a heap use-after-free vulnerability.
5
What could an attacker achieve by exploiting CVE-2024-42651?
An attacker could exploit CVE-2024-42651 to cause a Denial of Service (DoS) by sending a crafted SUBSCRIBE message.