CVE-2024-8376 - CVE House
Back to Database
Status published High CVE-2024-8376

Memory leak

Vulnerability Description

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8376

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Roman Kraus (Fraunhofer FOKUS)
  • Steffen Lüdtke (Fraunhofer FOKUS)
  • Martin Schneider (Fraunhofer FOKUS)
  • Ramon Barakat (Fraunhofer FOKUS)