USN-7441-1: Eclipse Mosquitto vulnerabilities
It was discovered that Eclipse Mosquitto client incorrectly handled memory when receiving a SUBACK packet. An attacker with a malicious broker could possibly use this issue to execute arbitrary code or cause a denial of service. (CVE-2024-10525) Xiangpu Song discovered that Eclipse Mosquitto broker did not properly manage memory under certain circumstances. A malicious client with a remote connection could possibly use this issue to cause the broker to crash resulting in a denial of service, or another unspecified impact. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-3935)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7441-1?
The vulnerability reported in USN-7441-1 can potentially lead to remote code execution or denial of service.
How do I fix USN-7441-1?
To remediate USN-7441-1, update to the recommended package versions available for your Ubuntu installation.
Which packages are affected by USN-7441-1?
USN-7441-1 affects multiple Mosquitto-related packages including libmosquitto1, mosquitto, and mosquitto-clients across several Ubuntu versions.
Can USN-7441-1 be exploited remotely?
Yes, USN-7441-1 can be exploited by an attacker via a malicious broker.
What systems are impacted by USN-7441-1?
Systems running Ubuntu 14.04, 16.04, 18.04, 20.04, 22.04, or 24.04 that have the affected Mosquitto packages installed are impacted by USN-7441-1.