PT-2024-8324 · Eclipse+4 · Eclipse Mosquitto+4

·

CVE-2024-3935

·

Published

2024-10-30

·

Updated

2026-03-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Mosquitto versions 2.0.0 through 2.0.18
Description The issue is related to a double free error in Eclipse Mosquitto. When a Mosquitto broker is configured to create an outgoing bridge connection with an incoming topic that uses topic remapping, a remote attacker can send a crafted PUBLISH packet to the broker, causing a double free error and subsequent crash of the broker. This can allow a remote attacker to cause a denial of service.
Recommendations For Eclipse Mosquitto versions 2.0.0 through 2.0.18, as a temporary workaround, consider disabling the topic remapping feature for incoming bridge connections until a patch is available. Restrict access to the Mosquitto broker to minimize the risk of exploitation. Avoid using the PUBLISH packet in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09880
CVE-2024-3935
DLA-4059-1
OESA-2024-2343
OESA-2024-2344
OESA-2024-2345
OESA-2024-2346
OPENSUSE-SU-2025:15074-1
OPENSUSE-SU-2026:20260-1
USN-7441-1

Affected Products

Debian
Eclipse Mosquitto
Linuxmint
Red Os
Ubuntu