Packages
- mosquitto - MQTT compatible message broker
Details
It was discovered that Eclipse Mosquitto client incorrectly handled
memory when receiving a SUBACK packet. An attacker with a malicious
broker could possibly use this issue to execute arbitrary code or
cause a denial of service. (CVE-2024-10525)
Xiangpu Song discovered that Eclipse Mosquitto broker did not properly
manage memory under certain circumstances. A malicious client with a
remote connection could possibly use this issue to cause the broker to
crash resulting in a denial of service, or another unspecified impact.
This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-3935)
It was discovered that Eclipse Mosquitto client incorrectly handled
memory when receiving a SUBACK packet. An attacker with a malicious
broker could possibly use this issue to execute arbitrary code or
cause a denial of service. (CVE-2024-10525)
Xiangpu Song discovered that Eclipse Mosquitto broker did not properly
manage memory under certain circumstances. A malicious client with a
remote connection could possibly use this issue to cause the broker to
crash resulting in a denial of service, or another unspecified impact.
This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-3935)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
24.04 noble | libmosquitto1 – 2.0.18-1ubuntu0.1~esm1 | ||
libmosquittopp1 – 2.0.18-1ubuntu0.1~esm1 | |||
mosquitto – 2.0.18-1ubuntu0.1~esm1 | |||
mosquitto-clients – 2.0.18-1ubuntu0.1~esm1 | |||
22.04 jammy | libmosquitto1 – 2.0.11-1ubuntu1.2 | ||
libmosquittopp1 – 2.0.11-1ubuntu1.2 | |||
mosquitto – 2.0.11-1ubuntu1.2 | |||
mosquitto-clients – 2.0.11-1ubuntu1.2 | |||
20.04 focal | libmosquitto1 – 1.6.9-1ubuntu0.1~esm2 | ||
libmosquittopp1 – 1.6.9-1ubuntu0.1~esm2 | |||
mosquitto – 1.6.9-1ubuntu0.1~esm2 | |||
mosquitto-clients – 1.6.9-1ubuntu0.1~esm2 | |||
18.04 bionic | libmosquitto1 – 1.4.15-2ubuntu0.18.04.3+esm2 | ||
libmosquittopp1 – 1.4.15-2ubuntu0.18.04.3+esm2 | |||
mosquitto – 1.4.15-2ubuntu0.18.04.3+esm2 | |||
mosquitto-clients – 1.4.15-2ubuntu0.18.04.3+esm2 | |||
16.04 xenial | libmosquitto1 – 1.4.8-1ubuntu0.16.04.7+esm2 | ||
libmosquittopp1 – 1.4.8-1ubuntu0.16.04.7+esm2 | |||
mosquitto – 1.4.8-1ubuntu0.16.04.7+esm2 | |||
mosquitto-clients – 1.4.8-1ubuntu0.16.04.7+esm2 | |||
14.04 trusty | libmosquitto0 – 0.15-2+deb7u3ubuntu0.1+esm1 | ||
libmosquittopp0 – 0.15-2+deb7u3ubuntu0.1+esm1 | |||
mosquitto – 0.15-2+deb7u3ubuntu0.1+esm1 | |||
mosquitto-clients – 0.15-2+deb7u3ubuntu0.1+esm1 | |||
python-mosquitto – 0.15-2+deb7u3ubuntu0.1+esm1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.