In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mosquitto | Eclipse | * | 2.0.16 (excluding) |
| Red Hat Satellite 6.13 for RHEL 8 | RedHat | mosquitto-0:2.0.17-1.el8sat | * |
| Red Hat Satellite 6.13 for RHEL 8 | RedHat | mosquitto-0:2.0.17-1.el8sat | * |
| Red Hat Satellite 6.14 for RHEL 8 | RedHat | mosquitto-0:2.0.17-1.el8sat | * |
| Red Hat Satellite 6.14 for RHEL 8 | RedHat | mosquitto-0:2.0.17-1.el8sat | * |
| Mosquitto | Ubuntu | bionic | * |
| Mosquitto | Ubuntu | esm-apps/focal | * |
| Mosquitto | Ubuntu | esm-apps/jammy | * |
| Mosquitto | Ubuntu | focal | * |
| Mosquitto | Ubuntu | jammy | * |
| Mosquitto | Ubuntu | lunar | * |
| Mosquitto | Ubuntu | trusty | * |
| Mosquitto | Ubuntu | upstream | * |
| Mosquitto | Ubuntu | xenial | * |