CVE-2024-8376: Memory leak
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8376?
CVE-2024-8376 is categorized as a high severity vulnerability due to its potential to cause memory leaks and segmentation faults.
What versions of Eclipse Mosquitto are affected by CVE-2024-8376?
Eclipse Mosquitto versions up to and including 2.0.18a are affected by CVE-2024-8376.
How do I fix CVE-2024-8376?
To mitigate CVE-2024-8376, upgrade to Eclipse Mosquitto version 2.0.19 or later.
What types of attacks does CVE-2024-8376 enable?
CVE-2024-8376 allows attackers to perform memory leaking, segmentation faults, or heap-use-after-free attacks through specific MQTT packet sequences.
Is there a workaround for CVE-2024-8376 if upgrading is not possible?
Currently, there are no documented workarounds for CVE-2024-8376, and upgrading is recommended.