{
  "threat_severity" : "Important",
  "public_date" : "2024-10-11T15:18:54Z",
  "bugzilla" : {
    "description" : "mosquitto: sending specific sequences of packets may trigger memory leak",
    "id" : "2318080",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2318080"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "(CWE-401|CWE-416|CWE-755)",
  "details" : [ "In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of \"CONNECT\", \"DISCONNECT\", \"SUBSCRIBE\", \"UNSUBSCRIBE\" and \"PUBLISH\" packets.", "A flaw was found in Eclipse Mosquitto. A remote attacker may be able to trigger memory leakage, segmentation fault, or a heap-use-after-free condition by sending specific sequences of \"CONNECT\", \"DISCONNECT\", \"SUBSCRIBE\", \"UNSUBSCRIBE\", and \"PUBLISH\" packets." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2024-10-31T00:00:00Z",
    "advisory" : "RHSA-2024:8718",
    "cpe" : "cpe:/a:redhat:satellite:6.14::el8",
    "package" : "mosquitto-0:2.0.19-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2024-10-31T00:00:00Z",
    "advisory" : "RHSA-2024:8718",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.14::el8",
    "package" : "mosquitto-0:2.0.19-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.15 for RHEL 8",
    "release_date" : "2024-10-31T00:00:00Z",
    "advisory" : "RHSA-2024:8719",
    "cpe" : "cpe:/a:redhat:satellite:6.15::el8",
    "package" : "mosquitto-0:2.0.19-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.15 for RHEL 8",
    "release_date" : "2024-10-31T00:00:00Z",
    "advisory" : "RHSA-2024:8719",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.15::el8",
    "package" : "mosquitto-0:2.0.19-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.16 for RHEL 8",
    "release_date" : "2024-11-05T00:00:00Z",
    "advisory" : "RHSA-2024:8906",
    "cpe" : "cpe:/a:redhat:satellite:6.16::el8",
    "package" : "mosquitto-0:2.0.19-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.16 for RHEL 8",
    "release_date" : "2024-11-05T00:00:00Z",
    "advisory" : "RHSA-2024:8906",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.16::el8",
    "package" : "mosquitto-0:2.0.19-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.16 for RHEL 9",
    "release_date" : "2024-11-05T00:00:00Z",
    "advisory" : "RHSA-2024:8906",
    "cpe" : "cpe:/a:redhat:satellite:6.16::el9",
    "package" : "mosquitto-0:2.0.19-1.el9sat"
  }, {
    "product_name" : "Red Hat Satellite 6.16 for RHEL 9",
    "release_date" : "2024-11-05T00:00:00Z",
    "advisory" : "RHSA-2024:8906",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.16::el9",
    "package" : "mosquitto-0:2.0.19-1.el9sat"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite-capsule:el8/mosquitto",
    "cpe" : "cpe:/a:redhat:satellite:6"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite:el8/mosquitto",
    "cpe" : "cpe:/a:redhat:satellite:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-8376\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-8376\nhttps://github.com/eclipse/mosquitto/releases/tag/v2.0.19\nhttps://gitlab.eclipse.org/security/cve-assignement/-/issues/26\nhttps://gitlab.eclipse.org/security/vulnerability-reports/-/issues/216\nhttps://gitlab.eclipse.org/security/vulnerability-reports/-/issues/217\nhttps://gitlab.eclipse.org/security/vulnerability-reports/-/issues/218\nhttps://gitlab.eclipse.org/security/vulnerability-reports/-/issues/227\nhttps://mosquitto.org/" ],
  "name" : "CVE-2024-8376",
  "csaw" : false
}