Negative SubACK Causes Out-of-Bounds Memory Access in Mosquitto Subscribers
CVE-2024-10525
9.8CRITICAL
What is CVE-2024-10525?
Eclipse Mosquitto clients, specifically those utilizing libmosquitto, are susceptible to an out of bounds memory access when a malicious broker transmits a crafted SUBACK packet devoid of reason codes. This vulnerability targets the mosquitto_sub and mosquitto_rr clients, posing a risk to data integrity and stability during subscription confirmations. It is crucial for users running versions 1.3.2 through 2.0.18 to upgrade to the latest version to mitigate potential exploitation risks.
Affected Version(s)
mosquitto 1.3.2 <= 2.0.18