In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access when acting in its onsubscribe callback. This affects the mosquittosub and mosquitto_rr clients.
{
"cna_assigner": "eclipse",
"cwe_ids": [
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10525.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10525.json"
[
{
"target": {
"function": "handle__suback",
"file": "lib/handle_suback.c"
},
"deprecated": false,
"source": "https://github.com/eclipse-mosquitto/mosquitto/commit/8ab20b4ba4204fdcdec78cb4d9f03c944a6e0e1c",
"id": "CVE-2024-10525-d05b89c8",
"signature_version": "v1",
"digest": {
"length": 1918.0,
"function_hash": "29036111489348541762894021766668069100"
},
"signature_type": "Function"
},
{
"target": {
"file": "lib/handle_suback.c"
},
"deprecated": false,
"source": "https://github.com/eclipse-mosquitto/mosquitto/commit/8ab20b4ba4204fdcdec78cb4d9f03c944a6e0e1c",
"id": "CVE-2024-10525-fcb71ac0",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"94950051260452402365347931505757235218",
"96581849340855976114804582782750664304",
"5849565670273732554841845849192978354",
"173389902800579440755348116221827973798"
]
},
"signature_type": "Line"
}
]
"2026-08-12T15:14:56Z"