A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nnimsggetpubpid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/33xxx/CVE-2023-33658.json",
"cna_assigner": "mitre"
}{
"cpe": "cpe:2.3:a:emqx:nanomq:0.17.2:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.17.2"
}
]
}[
{
"source": "https://github.com/nanomq/nanonng/commit/657e6c81c474bdee0e6413483b990e90610030c1",
"signature_version": "v1",
"target": {
"file": "src/mqtt/transport/tls/mqtt_tls.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"238118492306209824466591644182146651355",
"73288887871546130463872457436680809385",
"177105941187559162375076359119771007068",
"207873070159565122021798106817061692009",
"251535637674783221487029865388538538906",
"25049072818407312021974359505241147094"
],
"threshold": 0.9
},
"id": "CVE-2023-33658-01dcb896"
},
{
"source": "https://github.com/nanomq/nanonng/commit/657e6c81c474bdee0e6413483b990e90610030c1",
"signature_version": "v1",
"target": {
"function": "mqtts_tcptran_pipe_recv_cb",
"file": "src/mqtt/transport/tls/mqtt_tls.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 4133.0,
"function_hash": "23355315618923543829456620621903814504"
},
"id": "CVE-2023-33658-49d0f294"
},
{
"source": "https://github.com/nanomq/nanonng/commit/657e6c81c474bdee0e6413483b990e90610030c1",
"signature_version": "v1",
"target": {
"file": "src/sp/transport/mqtts/broker_tls.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"238118492306209824466591644182146651355",
"73288887871546130463872457436680809385",
"177105941187559162375076359119771007068",
"207873070159565122021798106817061692009",
"251535637674783221487029865388538538906",
"267540511822039535474325492904757792395"
],
"threshold": 0.9
},
"id": "CVE-2023-33658-580d1925"
},
{
"source": "https://github.com/nanomq/nanonng/commit/657e6c81c474bdee0e6413483b990e90610030c1",
"signature_version": "v1",
"target": {
"file": "src/sp/transport/mqttws/nmq_websocket.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"238118492306209824466591644182146651355",
"73288887871546130463872457436680809385",
"288820072418812848518883129616322670103",
"316830540005086130006695304258770817937",
"128755146118690718578875260463755633830",
"190776431000557197925574157618598627611",
"274107787091267991231922762036879666058"
],
"threshold": 0.9
},
"id": "CVE-2023-33658-7fedeeb2"
},
{
"source": "https://github.com/nanomq/nanonng/commit/657e6c81c474bdee0e6413483b990e90610030c1",
"signature_version": "v1",
"target": {
"function": "wstran_pipe_recv_cb",
"file": "src/sp/transport/mqttws/nmq_websocket.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 5556.0,
"function_hash": "53020928128498050841582651336808685927"
},
"id": "CVE-2023-33658-a3180052"
},
{
"source": "https://github.com/nanomq/nanonng/commit/657e6c81c474bdee0e6413483b990e90610030c1",
"signature_version": "v1",
"target": {
"function": "tlstran_pipe_recv_cb",
"file": "src/sp/transport/mqtts/broker_tls.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 5888.0,
"function_hash": "297247634546055184696329891679799654947"
},
"id": "CVE-2023-33658-e1698fa9"
}
]
"2026-05-19T06:03:16Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-33658.json"