NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://github.com/nanomq/nanomq | product |
https://github.com/nanomq/nanomq/issues/1217 | issue tracking exploit |
https://github.com/songxpu/bug_report/blob/master/MQTT/NanoMQ/CVE-2024-42651.md | exploit third party advisory |