MGASA-2025-0106

Source
https://advisories.mageia.org/MGASA-2025-0106.html
Import Source
https://advisories.mageia.org/MGASA-2025-0106.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2025-0106
Related
Published
2025-03-19T23:44:37Z
Modified
2025-03-19T23:11:21Z
Summary
Updated mosquitto packages fix security vulnerability
Details

The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc send function.

References
Credits

Affected packages

Mageia:9 / mosquitto

Package

Name
mosquitto
Purl
pkg:rpm/mageia/mosquitto?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.21-1.mga9

Ecosystem specific

{
    "section": "core"
}