PT-2024-8324 · Eclipse+4 · Eclipse Mosquitto+4

Song Xiangpu

+1

·

Published

2024-10-30

·

Updated

2026-03-29

·

CVE-2024-3935

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Mosquitto versions 2.0.0 through 2.0.18
Description The issue is related to a double free error in Eclipse Mosquitto. When a Mosquitto broker is configured to create an outgoing bridge connection with an incoming topic that uses topic remapping, a remote attacker can send a crafted PUBLISH packet to the broker, causing a double free error and subsequent crash of the broker. This can allow a remote attacker to cause a denial of service.
Recommendations For Eclipse Mosquitto versions 2.0.0 through 2.0.18, as a temporary workaround, consider disabling the topic remapping feature for incoming bridge connections until a patch is available. Restrict access to the Mosquitto broker to minimize the risk of exploitation. Avoid using the PUBLISH packet in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Double Free

Weakness Enumeration

Related Identifiers

BDU:2024-09880
CVE-2024-3935
DLA-4059-1
OESA-2024-2343
OESA-2024-2344
OESA-2024-2345
OESA-2024-2346
OPENSUSE-SU-2025:15074-1
OPENSUSE-SU-2026:20260-1
USN-7441-1

Affected Products

Debian
Eclipse Mosquitto
Linuxmint
Red Os
Ubuntu